CVE-2025-49193

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:*

History

26 Jan 2026, 19:30

Type Values Removed Values Added
References () https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF - () https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF - Broken Link
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf - Vendor Advisory
Summary
  • (es) La aplicación no implementa varios encabezados de seguridad. Estos encabezados ayudan a aumentar el nivel general de seguridad de la aplicación web, por ejemplo, impidiendo que la aplicación se muestre en un iFrame (ataques de clickjacking) o que se ejecute código JavaScript malicioso inyectado (ataques XSS).
CPE cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:*
First Time Sick field Analytics
Sick media Server
Sick tire Analytics
Sick
Sick logistic Diagnostic Analytics
Sick baggage Analytics
Sick package Analytics

12 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 15:15

Updated : 2026-01-26 19:30


NVD link : CVE-2025-49193

Mitre link : CVE-2025-49193

CVE.ORG link : CVE-2025-49193


JSON object : View

Products Affected

sick

  • media_server
  • package_analytics
  • logistic_diagnostic_analytics
  • field_analytics
  • tire_analytics
  • baggage_analytics
CWE
CWE-693

Protection Mechanism Failure