Executive brief
SICK TDC-x401GL gateway devices were found to use inadequate security measures for protecting stored passwords. This flaw could allow an attacker to more easily crack and extract user passwords if they gain access to the device's data. While the specific CVE identifier was later rejected by the authority, the underlying issue involves how the device secures credentials.
Technical details
The SICK TDC-x401GL firmware fails to use adequate salting mechanisms when hashing passwords (CWE-1391). This vulnerability allows an attacker with access to the password hashes to perform more efficient offline brute-force or rainbow table attacks to recover plaintext credentials. Although the CVE was marked as 'Rejected' by the CNA (SICK AG) in May 2026, the initial disclosure indicated a network-based attack vector. Security engineers should verify if the rejection was due to a duplicate entry or a fix being integrated into standard operating guidelines.
Affected products
- SICK AG TDC-x401GL firmware All versions prior to rejection
Timeline
- 2026-01-15: disclosed: Initial disclosure by SICK AG
- 2026-05-12: other: CVE rejected/withdrawn by SICK AG