Unrated severityNVD Advisory· Published Jun 12, 2025· Updated Oct 6, 2025
Missing HTTP Security Headers
CVE-2025-49193
Description
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).
Affected products
1- Range: all versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.jsonmitrevendor-advisoryx_csaf
- www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdfmitrevendor-advisory
- cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDFmitrex_SICK Operating Guidelines
- sick.com/psirtmitrex_SICK PSIRT Website
- www.cisa.gov/resources-tools/resources/ics-recommended-practicesmitrex_ICS-CERT recommended practices on Industrial Security
- www.first.org/cvss/calculator/3.1mitrex_CVSS v3.1 Calculator
News mentions
0No linked articles in our index yet.