Description
An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.
Published: 2026-02-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential SSH traffic observation or manipulation via weak CBC cipher suites
Action: Patch Firmware
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Users are strongly recommended to upgrade to release version 2.4.1.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Title Weak CBC Cipher Suites Allow Possible Compromise of SSH Communication

Fri, 06 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick
Sick lms1000
Sick lms1000 Firmware
Sick mrs1000
Sick mrs1000 Firmware
CPEs cpe:2.3:h:sick:lms1000:-:*:*:*:*:*:*:*
cpe:2.3:h:sick:mrs1000:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lms1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sick:mrs1000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sick
Sick lms1000
Sick lms1000 Firmware
Sick mrs1000
Sick mrs1000 Firmware

Fri, 27 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag sick Lms1000
Sick Ag sick Mrs1000
Vendors & Products Sick Ag
Sick Ag sick Lms1000
Sick Ag sick Mrs1000

Fri, 27 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
Description An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Sick Lms1000 Lms1000 Firmware Mrs1000 Mrs1000 Firmware
Sick Ag Sick Lms1000 Sick Mrs1000
cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2026-03-06T18:44:04.057Z

Reserved: 2026-01-29T15:06:29.934Z

Link: CVE-2026-1626

cve-icon Vulnrichment

Updated: 2026-03-06T18:43:57.677Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T09:16:15.863

Modified: 2026-03-05T02:13:42.007

Link: CVE-2026-1626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T15:30:06Z

Weaknesses