{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-02T06:21:00.090","vulnerabilities":[{"cve":{"id":"CVE-2026-1627","sourceIdentifier":"psirt@sick.de","published":"2026-02-27T09:16:16.050","lastModified":"2026-06-17T10:16:12.940","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic."},{"lang":"es","value":"Un atacante puede explotar el uso de algoritmos MAC obsoletos y débiles en el servicio SSH del dispositivo para comprometer potencialmente la integridad de la sesión SSH, permitiendo la manipulación de los datos transmitidos si el atacante puede interactuar con el tráfico de red."}],"affected":[{"source":"psirt@sick.de","affectedData":[{"vendor":"SICK AG","product":"SICK LMS1000","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"<=2.4.0","versionType":"custom","status":"affected"}]},{"vendor":"SICK AG","product":"SICK MRS1000","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"<=2.4.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@sick.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-27T17:00:57.624185Z","id":"CVE-2026-1627","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@sick.de","type":"Secondary","description":[{"lang":"en","value":"CWE-327"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:lms1000_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.4.1","matchCriteriaId":"88192768-5BFB-4267-BF9A-7D35C79DC6AA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:lms1000:-:*:*:*:*:*:*:*","matchCriteriaId":"909B274C-06A9-4AFB-A298-6E32A0BD11B7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:mrs1000_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.4.1","matchCriteriaId":"487CA09F-7ECD-4A1F-A2CF-DAA9FA6C68BF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:mrs1000:-:*:*:*:*:*:*:*","matchCriteriaId":"A99E9D30-4967-46EB-A046-8FD8718FD9EA"}]}]}],"references":[{"url":"https://sick.com/psirt","source":"psirt@sick.de","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices","source":"psirt@sick.de","tags":["US Government Resource"]},{"url":"https://www.first.org/cvss/calculator/3.1","source":"psirt@sick.de","tags":["Not Applicable"]},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0005.json","source":"psirt@sick.de","tags":["Vendor Advisory"]},{"url":"https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0005.pdf","source":"psirt@sick.de","tags":["Vendor Advisory"]},{"url":"https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf","source":"psirt@sick.de","tags":["Vendor Advisory"]}]}}]}