Browse all 114 CVE security advisories affecting SICK AG. AI-powered Chinese analysis, POCs, and references for each vulnerability.
SICK AG operates as a leading manufacturer of industrial sensors and safety systems, primarily serving automation and logistics sectors. Its product portfolio includes photoelectric sensors, laser scanners, and safety controllers designed for factory environments. Security analysis reveals a significant historical footprint of vulnerabilities, with 113 Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from web-based management interfaces or embedded software components. Notable incidents include critical flaws allowing unauthorized access to device configurations, potentially compromising industrial operations. The company has addressed many issues through firmware updates, yet the high volume of past vulnerabilities highlights persistent challenges in securing embedded industrial IoT devices. This track record underscores the necessity for rigorous security testing in critical infrastructure components, as exploitation could lead to operational disruptions or physical safety hazards in automated facilities.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-49200 | Unencrypted backup contains sensitive information — SICK Field Analytics CWE-200 | 6.5 | Medium | 2025-06-12 |
| CVE-2025-49199 | Backup files can be modified and uploaded — SICK Field Analytics CWE-345 | 8.8 | High | 2025-06-12 |
| CVE-2025-49196 | Deprecated TLS version supported — SICK Field Analytics CWE-327 | 6.5 | Medium | 2025-06-12 |
| CVE-2025-49192 | Clickjacking — SICK Field Analytics CWE-1021 | 4.3 | Medium | 2025-06-12 |
| CVE-2025-49191 | Dashboards and iFrames can link malicious web content — SICK Field Analytics CWE-1021 | 4.8 | Medium | 2025-06-12 |
| CVE-2025-49190 | Server-Side Request Forgery — SICK Field Analytics CWE-918 | 4.3 | Medium | 2025-06-12 |
| CVE-2025-49188 | Sensitive Data in URL — SICK Field Analytics CWE-598 | 5.3 | Medium | 2025-06-12 |
| CVE-2025-49187 | User enumeration — SICK Field Analytics CWE-204 | 5.3 | Medium | 2025-06-12 |
| CVE-2025-49185 | Stored Cross-Site-Script — SICK Field Analytics CWE-79 | 5.5 | Medium | 2025-06-12 |
This page lists every published CVE security advisory associated with SICK AG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.