CVE-2026-1626 PUBLISHED

Assigner: SICK AG
Reserved: 29.01.2026 Published: 27.02.2026 Updated: 27.02.2026

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor SICK AG
Product SICK LMS1000
Versions Default: unaffected
  • affected from 0 to <=2.4.0 (incl.)
Vendor SICK AG
Product SICK MRS1000
Versions Default: unaffected
  • affected from 0 to <=2.4.0 (incl.)

Solutions

Users are strongly recommended to upgrade to release version 2.4.1.

References

Problem Types

  • CWE-327 Use of a Broken or Risky Cryptographic Algorithm CWE