OEE
by SICK AG
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27578 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2022 | An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content. | ||
| CVE-2025-59461 | Hig | 0.49 | 7.6 | 0.00 | Oct 27, 2025 | A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services. | ||
| CVE-2025-58580 | Med | 0.42 | 6.5 | 0.00 | Oct 6, 2025 | An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example. | ||
| CVE-2025-58585 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering. | ||
| CVE-2025-58582 | Med | 0.34 | 5.3 | 0.01 | Oct 6, 2025 | If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged. | ||
| CVE-2025-58579 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration. | ||
| CVE-2025-27451 | Med | 0.34 | 5.3 | 0.00 | Jul 3, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | ||
| CVE-2025-9913 | Med | 0.29 | 4.5 | 0.00 | Oct 6, 2025 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. | ||
| CVE-2025-59463 | Med | 0.28 | 4.3 | 0.00 | Oct 27, 2025 | An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers. | ||
| CVE-2025-58581 | Med | 0.28 | 4.3 | 0.00 | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application. | ||
| CVE-2025-58589 | Low | 0.18 | 2.7 | 0.00 | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. |
- risk 0.51cvss 7.8epss 0.00
An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.
- risk 0.49cvss 7.6epss 0.00
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
- risk 0.42cvss 6.5epss 0.00
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
- risk 0.34cvss 5.3epss 0.00
Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.
- risk 0.34cvss 5.3epss 0.01
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
- risk 0.34cvss 5.3epss 0.00
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
- risk 0.34cvss 5.3epss 0.00
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
- risk 0.29cvss 4.5epss 0.00
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.
- risk 0.28cvss 4.3epss 0.00
An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.
- risk 0.28cvss 4.3epss 0.00
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
- risk 0.18cvss 2.7epss 0.00
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.