Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET
requests to gather sensitive information. An attacker could also send HTTP POST requests to modify
the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service
attack.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack. | |
Title | Configurations endpoint does not require authorization | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: SICK AG
Published: 2025-06-12T13:14:07.750Z
Updated: 2025-06-12T13:26:27.281Z
Reserved: 2025-06-03T05:55:52.771Z
Link: CVE-2025-49181

Updated: 2025-06-12T13:26:23.985Z

Status : Awaiting Analysis
Published: 2025-06-12T14:15:30.270
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-49181

No data.