CVE-2025-58581 Details
Description
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
A vulnerability exists in SICK Enterprise Analytics and SICK Logistic Analytics products, all versions, allowing unauthorized access to sensitive information. This issue arises from improper authorization of configuration settings, which enables remote attackers to gather internal application data. Additionally, when errors occur, the application reveals full stack traces, including class and method names, which can be exploited to understand the application's structure and technology stack.
Users are advised to ensure that only trusted entities have access to the device. It is also recommended to follow the SICK Operating Guidelines and the ICS-CERT recommended practices for Industrial Security to create a protected IT environment.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sick enterprise analytics | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2026 | Initial Analysis | [email protected] |
| Oct 6, 2025 | New CVE Received | [email protected] |