CVE-2025-49184 Details
Description
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.
A remote unauthorized attacker can access sensitive application information due to a lack of proper authorization on a configuration settings endpoint. This vulnerability affects SICK Field Analytics all versions and SICK Media Server versions through 1.4. Exploitation involves sending unencrypted HTTP requests to the vulnerable endpoint, which can lead to unauthorized information access or modification.
Users of SICK Media Server are advised to upgrade to version 1.5 or later. For SICK Field Analytics, ensure that only trusted entities have access to the device and follow the SICK Operating Guidelines and ICS-CERT recommended practices for Industrial Security.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sick baggage analytics | All versions |
CPE
Remediation
| |
| sick enterprise analytics | All versions |
CPE
Remediation
| |
| sick field analytics | All versions |
CPE
Remediation
| |
| sick logistic diagnostic analytics | All versions |
CPE
Remediation
| |
| sick package analytics | All versions |
CPE
Remediation
| |
| sick tire analytics | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Jun 12, 2025 | New CVE Received | [email protected] |