A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSick Baggage Analytics
APPSickall versionsSick Enterprise Analytics
APPSickall versionsSick Field Analytics
APPSickall versionsSick Logistic Diagnostic Analytics
APPSickall versionsSick Package Analytics
APPSickall versionsSick Tire Analytics
APPSickall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-2076CRITICAL9.8PL ✓same product
Obejście uwierzytelniania w SICK Package Analytics przez REST API
CVE-2025-49199HIGH8.8same product
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a ...
CVE-2020-2077HIGH7.5same product
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...
CVE-2025-58579MEDIUM5.3same product
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...
CVE-2025-58580MEDIUM6.5same product
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient va...