SICK AG Baggage Analytics是德国SICK AG公司的一款用于机场追踪系统的可视化和分析软件。 SICK AG Baggage Analytics存在安全漏洞,该漏洞源于登录失败时返回不同错误信息,可能导致用户名枚举攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SICK AG | Baggage Analytics | < 4.6.3 |
affected |
| SICK AG | Enterprise Analytics | all versions |
affected |
| SICK AG | Logistic Diagnostic Analytics | < 4.6.3 |
affected |
| SICK AG | Package Analytics | < 4.6.3 |
affected |
| SICK AG | Tire Analytics | < 4.6.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SICK AG | Baggage Analytics | 0 ~ 4.6.3 | - |
|
| SICK AG | Tire Analytics | 0 ~ 4.6.3 | - |
|
| SICK AG | Package Analytics | 0 ~ 4.6.3 | - |
|
| SICK AG | Logistic Diagnostic Analytics | 0 ~ 4.6.3 | - |
|
| SICK AG | Enterprise Analytics | all versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-58587 | 6.5 MEDIUM | Improper Restriction of Excessive Authentication Attempts |
| CVE-2025-58580 | 6.5 MEDIUM | Injection via log file |
| CVE-2025-58590 | 6.5 MEDIUM | Path traversal |
| CVE-2025-58591 | 6.5 MEDIUM | Path Traversal |
| CVE-2025-58582 | 5.3 MEDIUM | Uncontrolled Resource Consumption via log file |
| CVE-2025-58585 | 5.3 MEDIUM | Sensitive Information Disclosure Through Missing Authentication |
| CVE-2025-58583 | 5.3 MEDIUM | User Enumeration |
| CVE-2025-58584 | 5.3 MEDIUM | Plain Text Transmission of Username and Password in the URL |
| CVE-2025-58579 | 5.3 MEDIUM | Username Disclosure Through Missing Authentication |
| CVE-2025-9913 | 4.5 MEDIUM | Cross Site Scripting: Session Hijacking |
| CVE-2025-58581 | 4.3 MEDIUM | Information Disclosure Through Stacktrace-/MQTT/Config/changeAll |
| CVE-2025-9914 | 4.3 MEDIUM | SICK AG Baggage Analytics 安全漏洞 |
| CVE-2025-58578 | 3.8 LOW | Unlimited user creation by authorized users |
| CVE-2025-58589 | 2.7 LOW | Information Disclosure Through Stacktrace |
No comments yet