CVE-2026-1627 PUBLISHED

Assigner: SICK AG
Reserved: 29.01.2026 Published: 27.02.2026 Updated: 27.02.2026

An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor SICK AG
Product SICK LMS1000
Versions Default: unaffected
  • affected from 0 to <=2.4.0 (incl.)
Vendor SICK AG
Product SICK MRS1000
Versions Default: unaffected
  • affected from 0 to <=2.4.0 (incl.)

Solutions

Users are strongly recommended to upgrade to release version 2.4.1.

References

Problem Types

  • CWE-327 Use of a Broken or Risky Cryptographic Algorithm CWE