requests to gather sensitive information. An attacker could also send HTTP POST requests to modify
the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service
attack.
Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
It is possible to enable the authorization of the API endpoint via licence. Please contact your support to get a licence with API authorization enabled.
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack. | |
Title | Configurations endpoint does not require authorization | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2025-06-12T13:26:27.281Z
Reserved: 2025-06-03T05:55:52.771Z
Link: CVE-2025-49181

Updated: 2025-06-12T13:26:23.985Z

Status : Awaiting Analysis
Published: 2025-06-12T14:15:30.270
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-49181

No data.

No data.