CVE-2026-1626

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sick:lms1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:lms1000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sick:mrs1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:mrs1000:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:16

Type Values Removed Values Added
Summary
  • (es) Un atacante puede explotar el uso de suites de cifrado débiles basadas en CBC en el servicio SSH del dispositivo para potencialmente observar o manipular partes de la comunicación SSH cifrada, si son capaces de interceptar o interactuar con el tráfico de red.

05 Mar 2026, 02:13

Type Values Removed Values Added
First Time Sick lms1000
Sick mrs1000
Sick
Sick lms1000 Firmware
Sick mrs1000 Firmware
CPE cpe:2.3:h:sick:mrs1000:-:*:*:*:*:*:*:*
cpe:2.3:h:sick:lms1000:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lms1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sick:mrs1000_firmware:*:*:*:*:*:*:*:*
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0005.json - () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0005.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0005.pdf - () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0005.pdf - Vendor Advisory
References () https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf - () https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf - Vendor Advisory

27 Feb 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 09:16

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1626

Mitre link : CVE-2026-1626

CVE.ORG link : CVE-2026-1626


JSON object : View

Products Affected

sick

  • mrs1000_firmware
  • lms1000
  • mrs1000
  • lms1000_firmware
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm