Authentication Flaw in Sick Product Enables User Enumeration
CVE-2025-58579
5.3MEDIUM
Key Information:
- Vendor
Sick Ag
- Vendor
- CVE Published:
- 6 October 2025
What is CVE-2025-58579?
An authentication flaw exists in the SICK Application that allows unauthenticated users to query the API endpoint, potentially leading to unauthorized access and user enumeration. Attackers could exploit this weakness to gather information about users, increasing the risk of targeted attacks. It is crucial for organizations using affected versions to implement appropriate security measures to mitigate this vulnerability.
Affected Version(s)
Baggage Analytics all versions
Enterprise Analytics all versions
Logistic Diagnostic Analytics all versions
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
