Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSick Baggage Analytics
APPSickall versionsSick Logistic Diagnostic Analytics
APPSickall versionsSick Package Analytics
APPSickall versionsSick Tire Analytics
APPSickall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-2076CRITICAL9.8PL ✓same product
Obejście uwierzytelniania w SICK Package Analytics przez REST API
CVE-2025-49184HIGH7.5same product
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...
CVE-2020-2077HIGH7.5same product
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...
CVE-2025-58579MEDIUM5.3same product
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...
CVE-2025-58584MEDIUM5.3same product
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URL...