CVE Database
/

CVE-2025-49193

Back to search

CVE-2025-49193

Published: Jun 12, 2025

Modified: May 13, 2026

PUBLISHED

CVSS v3.1

4.2

MEDIUM

Description

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

VendorProductVersions

SICK AG

Field Analytics

affected
all versions

SICK AG

Media Server

affected
0 - < 1.5

SICK AG

Baggage Analytics

affected
0 - < 4.6.3

SICK AG

Tire Analytics

affected
0 - < 4.6.3

SICK AG

Package Analytics

affected
0 - < 4.6.3

SICK AG

Logistic Diagnostic Analytics

affected
0 - < 4.6.3

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now