CVE-2026-22908

9.1

SICK AG · TDC-X401GL

SICK AG TDC-X401GL devices are vulnerable to incorrect privilege assignment when processing unvalidated container images, potentially allowing authenticated remote attackers to gain full system access.

Executive summary

A critical privilege escalation vulnerability in SICK AG TDC-X401GL allows authenticated remote attackers to gain full system access through the upload of malicious container images.

Vulnerability

The issue (CWE-266) involves incorrect privilege assignment during the processing of container images. While the CVSS vector indicates high privileges are required (PR:H), successful exploitation leads to total system compromise.

Business impact

An attacker with administrative access can exploit this flaw to escalate their privileges, potentially gaining full control over the device and its associated industrial functions. Given the CVSS score of 9.1, the business impact includes the potential for unauthorized process modification, data theft, and significant operational disruption.

Remediation

Immediate Action: Upgrade all SICK AG TDC-X401GL units to firmware version 1.4.0 or later immediately.

Proactive Monitoring: Audit logs for administrative actions and monitor for any suspicious container image uploads or unexpected changes to system configurations.

Compensating Controls: Restrict administrative access to the device to only essential personnel and use secure, authenticated channels for all administrative operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Although this vulnerability requires high privileges, the catastrophic potential for full system compromise necessitates immediate action. Administrators should verify their current firmware version and apply the 1.4.0 update at the earliest opportunity to ensure the integrity of the TDC-X401GL environment.