An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
References
| Link | Resource |
|---|---|
| https://sick.com/psirt | Vendor Advisory |
| https://www.cisa.gov/resources-tools/resources/ics-recommended-practices | US Government Resource |
| https://www.first.org/cvss/calculator/3.1 | Not Applicable |
| https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json | Vendor Advisory |
| https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf | Vendor Advisory |
| https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf | Product |
Configurations
History
27 Jan 2026, 17:27
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://sick.com/psirt - Vendor Advisory | |
| References | () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource | |
| References | () https://www.first.org/cvss/calculator/3.1 - Not Applicable | |
| References | () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json - Vendor Advisory | |
| References | () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf - Vendor Advisory | |
| References | () https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf - Product | |
| CPE | cpe:2.3:a:sick:enterprise_analytics:*:*:*:*:*:*:*:* | |
| First Time |
Sick enterprise Analytics
Sick |
06 Oct 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-06 07:15
Updated : 2026-01-27 17:27
NVD link : CVE-2025-58580
Mitre link : CVE-2025-58580
CVE.ORG link : CVE-2025-58580
JSON object : View
Products Affected
sick
- enterprise_analytics
CWE
CWE-117
Improper Output Neutralization for Logs
