CVE-2026-22920
Published: 15 January 2026
Summary
CVE-2026-22920 is a low-severity Use of Weak Credentials (CWE-1391) vulnerability in Sick Tdc-X401Gl Firmware. Its CVSS base score is 3.7 (Low).
Operationally, exploitation aligns with the MITRE ATT&CK technique Password Cracking (T1110.002); ranked at the 5.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Threat & Defense at a Glance
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Lack of salting enables offline password cracking and indicates insecure credential storage/extraction on the device.
NVD Description
The device's passwords have not been adequately salted, making them vulnerable to password extraction attacks.
Deeper analysisAI
CVE-2026-22920 affects SICK devices, where passwords are not adequately salted, rendering them vulnerable to password extraction attacks. Published on 2026-01-15, the vulnerability carries a CVSS v3.1 base score of 3.7 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) and is associated with CWE-1391.
Attackers with network access can exploit this vulnerability without privileges or user interaction, though it requires high attack complexity. Successful exploitation enables low-impact confidentiality breaches, specifically the extraction of unsalted passwords from the device.
Mitigation details are available in SICK's PSIRT advisory at https://sick.com/psirt and the associated CSAF provider document sca-2026-0001 (JSON: https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.json; PDF: https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.pdf). Additional resources include CISA ICS recommended practices (https://www.cisa.gov/resources-tools/resources/ics-recommended-practices) and the FIRST CVSS v3.1 calculator (https://www.first.org/cvss/calculator/3.1).
Details
- CWE(s)