Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SICK AG — Vulnerabilities & Security Advisories 114

Browse all 114 CVE security advisories affecting SICK AG. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SICK AG operates as a leading manufacturer of industrial sensors and safety systems, primarily serving automation and logistics sectors. Its product portfolio includes photoelectric sensors, laser scanners, and safety controllers designed for factory environments. Security analysis reveals a significant historical footprint of vulnerabilities, with 113 Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from web-based management interfaces or embedded software components. Notable incidents include critical flaws allowing unauthorized access to device configurations, potentially compromising industrial operations. The company has addressed many issues through firmware updates, yet the high volume of past vulnerabilities highlights persistent challenges in securing embedded industrial IoT devices. This track record underscores the necessity for rigorous security testing in critical infrastructure components, as exploitation could lead to operational disruptions or physical safety hazards in automated facilities.

CVE ID Title CVSS Severity Published
CVE-2025-58589 Information Disclosure Through Stacktrace — Baggage Analytics CWE-200 2.7 Low 2025-10-06
CVE-2025-58587 Improper Restriction of Excessive Authentication Attempts — Baggage Analytics CWE-307 6.5 Medium 2025-10-06
CVE-2025-58586 User Enumeration by excessive error output — Baggage Analytics CWE-204 5.3 Medium 2025-10-06
CVE-2025-58585 Sensitive Information Disclosure Through Missing Authentication — Baggage Analytics CWE-497 5.3 Medium 2025-10-06
CVE-2025-58584 Plain Text Transmission of Username and Password in the URL — Baggage Analytics CWE-598 5.3 Medium 2025-10-06
CVE-2025-58583 User Enumeration — Enterprise Analytics CWE-497 5.3 Medium 2025-10-06
CVE-2025-58582 Uncontrolled Resource Consumption via log file — Enterprise Analytics CWE-770 5.3 Medium 2025-10-06
CVE-2025-58581 Information Disclosure Through Stacktrace-/MQTT/Config/changeAll — Enterprise Analytics CWE-200 4.3 Medium 2025-10-06
CVE-2025-58580 Injection via log file — Enterprise Analytics CWE-117 6.5 Medium 2025-10-06
CVE-2025-58578 Unlimited user creation by authorized users — Enterprise Analytics CWE-770 3.8 Low 2025-10-06
CVE-2025-9914 SICK AG Baggage Analytics 安全漏洞 — Baggage Analytics CWE-288 4.3 Medium 2025-10-06
CVE-2025-9913 Cross Site Scripting: Session Hijacking — Baggage Analytics CWE-79 4.5 Medium 2025-10-06
CVE-2025-49200 Unencrypted backup contains sensitive information — SICK Field Analytics CWE-200 6.5 Medium 2025-06-12
CVE-2025-49199 Backup files can be modified and uploaded — SICK Field Analytics CWE-345 8.8 High 2025-06-12
CVE-2025-49198 Poor quality of randomness in authorization tokens — SICK Media Server CWE-330 3.1 Low 2025-06-12
CVE-2025-49197 Deprecated TLS version supported — SICK Media Server CWE-328 6.5 Medium 2025-06-12
CVE-2025-49196 Deprecated TLS version supported — SICK Field Analytics CWE-327 6.5 Medium 2025-06-12
CVE-2025-49195 No protection against brute-force attacks — SICK Media Server CWE-307 5.3 Medium 2025-06-12
CVE-2025-49194 Unencrypted communication — SICK Media Server CWE-319 7.5 High 2025-06-12
CVE-2025-49193 Missing HTTP Security Headers — Field Analytics CWE-693 4.2 Medium 2025-06-12
CVE-2025-49192 Clickjacking — SICK Field Analytics CWE-1021 4.3 Medium 2025-06-12
CVE-2025-49191 Dashboards and iFrames can link malicious web content — SICK Field Analytics CWE-1021 4.8 Medium 2025-06-12
CVE-2025-49190 Server-Side Request Forgery — SICK Field Analytics CWE-918 4.3 Medium 2025-06-12
CVE-2025-49189 Cookie missing HttpOnly flag — SICK Media Server CWE-1004 5.3 Medium 2025-06-12
CVE-2025-49188 Sensitive Data in URL — SICK Field Analytics CWE-598 5.3 Medium 2025-06-12
CVE-2025-49187 User enumeration — SICK Field Analytics CWE-204 5.3 Medium 2025-06-12
CVE-2025-49186 No brute-force protection — Field Analytics CWE-307 5.3 Medium 2025-06-12
CVE-2025-49185 Stored Cross-Site-Script — SICK Field Analytics CWE-79 5.5 Medium 2025-06-12
CVE-2025-49184 Information disclosure to unauthorized user — Field Analytics CWE-200 7.5 High 2025-06-12
CVE-2025-49183 Unencrypted communication (HTTP) — SICK Media Server CWE-319 7.5 High 2025-06-12

This page lists every published CVE security advisory associated with SICK AG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.