Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18192 | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks). |
Solution
Media Server: Users are strongly recommended to upgrade to the latest release of Media Server (>= 1.5).
Workaround
Field Analytics: Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The collected resources \"SICK Operating Guidelines\" and \"ICS-CERT recommended practices on Industrial Security\" could help to implement the general security practices.
Mon, 26 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sick
Sick baggage Analytics Sick field Analytics Sick logistic Diagnostic Analytics Sick media Server Sick package Analytics Sick tire Analytics |
|
| CPEs | cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:* cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sick
Sick baggage Analytics Sick field Analytics Sick logistic Diagnostic Analytics Sick media Server Sick package Analytics Sick tire Analytics |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks). | |
| Title | Missing HTTP Security Headers | |
| Weaknesses | CWE-693 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2025-10-06T07:23:25.144Z
Reserved: 2025-06-03T05:58:15.616Z
Link: CVE-2025-49193
Updated: 2025-06-12T14:33:47.471Z
Status : Analyzed
Published: 2025-06-12T15:15:39.433
Modified: 2026-01-26T19:30:49.307
Link: CVE-2025-49193
No data.
OpenCVE Enrichment
No data.
EUVD