Media Server Authorization Token Vulnerability in SICK Products
CVE-2025-49198

3.1LOW

Key Information:

Vendor

Sick Ag

Vendor
CVE Published:
12 June 2025

What is CVE-2025-49198?

The Media Server from SICK exhibits a security issue where the randomness of authorization tokens is inadequate. This flaw enables attackers to potentially guess valid active user tokens, which could lead to unauthorized access and manipulation of user sessions. Organizations utilizing this Media Server are advised to review their security protocols and consider updating their systems to mitigate potential risks associated with this vulnerability.

Affected Version(s)

SICK Media Server all versions

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.