The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.
History

Tue, 17 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.
Title Backup files can be modified and uploaded
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published: 2025-06-12T14:26:32.507Z

Updated: 2025-06-17T19:02:18.155Z

Reserved: 2025-06-03T05:58:15.617Z

Link: CVE-2025-49199

cve-icon Vulnrichment

Updated: 2025-06-12T14:40:48.326Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-12T15:15:40.270

Modified: 2025-06-12T16:06:20.180

Link: CVE-2025-49199

cve-icon Redhat

No data.