High severity8.8NVD Advisory· Published Jun 12, 2025· Updated Jun 17, 2026
CVE-2025-49199
CVE-2025-49199
Description
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- SICK AG/SICK Field Analyticsv5Range: all versions
Patches
Vulnerability mechanics
References
6- sick.com/psirtnvdVendor Advisory
- www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.jsonnvdVendor Advisory
- www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdfnvdVendor Advisory
- cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDFnvdBroken Link
- www.cisa.gov/resources-tools/resources/ics-recommended-practicesnvdUS Government Resource
- www.first.org/cvss/calculator/3.1nvdNot Applicable
News mentions
0No linked articles in our index yet.