Authentication Exposure in SICK Products Due to URL Parameter Transmission
CVE-2025-58584
5.3MEDIUM
Key Information:
- Vendor
Sick Ag
- Vendor
- CVE Published:
- 6 October 2025
What is CVE-2025-58584?
This vulnerability arises from the practice of transmitting usernames and passwords directly in the URL as parameters during HTTP requests. Such a method is inherently insecure as URLs can be logged by servers, stored in browser histories, or cached by proxy servers, leading to an inadvertent disclosure of sensitive authentication data. Organizations utilizing affected SICK products must address this issue to enhance their security posture and protect user data from exposure.
Affected Version(s)
Baggage Analytics all versions
Enterprise Analytics all versions
Logistic Diagnostic Analytics all versions
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
