Unsecured Backup ZIPs in SICK Products Lead to Potential Application Disruption
CVE-2025-49199
8.8HIGH
What is CVE-2025-49199?
The application lacks proper signing of backup ZIP files, which exposes a significant security risk. Attackers can exploit this vulnerability by downloading, altering, and re-uploading backup ZIPs. This manipulation can lead to severe disruptions in application functionality, such as misconfiguring services, preventing them from running successfully. Furthermore, attackers may redirect internal traffic to malicious services under their control, potentially leading to unauthorized data access and information theft.
Affected Version(s)
SICK Field Analytics all versions
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
