Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 13 Jun 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 |
Fri, 13 Jun 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-540 |
Thu, 12 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Configurations endpoint does not require authorization | Credential disclosure |
Thu, 12 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application. | |
| Title | Configurations endpoint does not require authorization | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SICK AG
Published: 2025-06-12T13:15:02.172Z
Updated: 2025-06-16T16:46:15.519Z
Reserved: 2025-06-03T05:55:52.772Z
Link: CVE-2025-49182
Updated: 2025-06-12T13:25:49.573Z
Status : Awaiting Analysis
Published: 2025-06-12T14:15:30.437
Modified: 2025-06-13T09:15:20.130
Link: CVE-2025-49182
No data.