CVE-2025-49192

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while clicking on seemingly innocuous objects.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sick:field_analytics:-:*:*:*:*:*:*:*
cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:*

History

06 Feb 2026, 14:30

Type Values Removed Values Added
Summary
  • (es) La aplicación web es vulnerable a ataques de clickjacking. El sitio puede estar incrustado en otro frame, lo que permite a un atacante engañar al usuario para que haga clic en algo distinto a lo que percibe. Esto podría revelar información confidencial o permitir que otros tomen el control de su ordenador mientras hacen clic en objetos aparentemente inofensivos.
First Time Sick field Analytics
Sick media Server
Sick
CPE cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:field_analytics:-:*:*:*:*:*:*:*
References () https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF - () https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF - Broken Link
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf - Vendor Advisory

12 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 15:15

Updated : 2026-02-06 14:30


NVD link : CVE-2025-49192

Mitre link : CVE-2025-49192

CVE.ORG link : CVE-2025-49192


JSON object : View

Products Affected

sick

  • media_server
  • field_analytics
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames