Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the application's internal structure and discover other, more critical vulnerabilities.
References
| Link | Resource |
|---|---|
| https://sick.com/psirt | Vendor Advisory |
| https://www.cisa.gov/resources-tools/resources/ics-recommended-practices | US Government Resource |
| https://www.first.org/cvss/calculator/3.1 | Not Applicable |
| https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.json | Vendor Advisory |
| https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.pdf | Vendor Advisory |
| https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf | Product |
Configurations
History
29 Jan 2026, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sick:incoming_goods_suite:*:*:*:*:*:*:*:* | |
| First Time |
Sick
Sick incoming Goods Suite |
|
| References | () https://sick.com/psirt - Vendor Advisory | |
| References | () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource | |
| References | () https://www.first.org/cvss/calculator/3.1 - Not Applicable | |
| References | () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.json - Vendor Advisory | |
| References | () https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.pdf - Vendor Advisory | |
| References | () https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf - Product |
15 Jan 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-15 14:16
Updated : 2026-01-29 16:18
NVD link : CVE-2026-22646
Mitre link : CVE-2026-22646
CVE.ORG link : CVE-2026-22646
JSON object : View
Products Affected
sick
- incoming_goods_suite
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
