The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NAvaya Media Server
APPAvayaall versionsSick Baggage Analytics
APPSickall versionsSick Field Analytics
APPSickall versionsSick Logistic Diagnostic Analytics
APPSickall versionsSick Package Analytics
APPSickall versionsSick Tire Analytics
APPSickall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-2076CRITICAL9.8PL ✓same product
Obejście uwierzytelniania w SICK Package Analytics przez REST API
CVE-2025-49184HIGH7.5same product
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...
CVE-2025-49199HIGH8.8same product
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a ...
CVE-2020-2077HIGH7.5same product
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...
CVE-2007-2374HIGH9.3same product
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers...