High severity8.6NVD Advisory· Published Jun 12, 2025· Updated Jun 17, 2026
CVE-2025-49181
CVE-2025-49181
Description
Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- SICK AG/SICK Media Serverv5Range: all versions
Patches
Vulnerability mechanics
References
6- sick.com/psirtnvdVendor Advisory
- www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.jsonnvdVendor Advisory
- www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdfnvdVendor Advisory
- cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDFnvdBroken Link
- www.cisa.gov/resources-tools/resources/ics-recommended-practicesnvdUS Government Resource
- www.first.org/cvss/calculator/3.1nvdNot Applicable
News mentions
0No linked articles in our index yet.