CRITICAL🇵🇱 Wersja polska

CVE-2020-2076

CVSS 9.8v3.1pub. 2020-07-29upd. 2024-11-21

SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sick Package Analytics

    APP
    Sick
    ≤ 04.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-49184HIGH7.5same product

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...

CVE-2020-2077HIGH7.5same product

SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...

CVE-2025-58584MEDIUM5.3same product

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URL...

CVE-2025-58579MEDIUM5.3same product

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...

CVE-2025-58585MEDIUM5.3same product

Multiple endpoints with sensitive information do not require authentication, making the application susceptibl...