CVE-2025-58579 Details
Description
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
A vulnerability allowing user enumeration has been identified in SICK Enterprise Analytics and SICK Logistic Analytics products. This issue arises from a lack of authentication on certain endpoints, enabling unauthenticated users to request data and gather information about users. The vulnerability could potentially be exploited to bypass authentication and access sensitive information, as the application provides access to a login-protected H2 database for caching purposes, with usernames prefilled.
Users are advised to ensure that only trusted entities have access to the affected SICK Enterprise Analytics and SICK Logistic Analytics products. Additionally, general security measures should be applied when operating these products. SICK's Operating Guidelines and ICS-CERT recommended practices on Industrial Security can provide further assistance in implementing these security practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sick baggage analytics | All versions |
CPE
Remediation
| |
| sick enterprise analytics | All versions |
CPE
Remediation
| |
| sick logistic diagnostic analytics | All versions |
CPE
Remediation
| |
| sick package analytics | All versions |
CPE
Remediation
| |
| sick tire analytics | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2026 | Initial Analysis | [email protected] |
| Oct 6, 2025 | New CVE Received | [email protected] |