MEDIUM🇵🇱 Wersja polska

CVE-2025-58584

CVSS 5.3v3.1pub. 2025-10-06upd. 2026-01-27

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Sick Baggage Analytics

    APP
    Sick
    all versions
  • Sick Enterprise Analytics

    APP
    Sick
    all versions
  • Sick Logistic Diagnostic Analytics

    APP
    Sick
    all versions
  • Sick Package Analytics

    APP
    Sick
    all versions
  • Sick Tire Analytics

    APP
    Sick
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-2076CRITICAL9.8PL ✓same product

Obejście uwierzytelniania w SICK Package Analytics przez REST API

CVE-2025-49184HIGH7.5same product

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...

CVE-2020-2077HIGH7.5same product

SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...

CVE-2025-58579MEDIUM5.3same product

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...

CVE-2025-58580MEDIUM6.5same product

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient va...