VYPR

OEE

by SICK AG

CVEs (11)

  • CVE-2022-27578HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.

  • CVE-2025-59461HigOct 27, 2025
    risk 0.49cvss 7.6epss 0.00

    A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

  • CVE-2025-58580MedOct 6, 2025
    risk 0.42cvss 6.5epss 0.00

    An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.

  • CVE-2025-58585MedOct 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

  • CVE-2025-58582MedOct 6, 2025
    risk 0.34cvss 5.3epss 0.01

    If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

  • CVE-2025-58579MedOct 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.

  • CVE-2025-27451MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

  • CVE-2025-9913MedOct 6, 2025
    risk 0.29cvss 4.5epss 0.00

    JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

  • CVE-2025-59463MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

  • CVE-2025-58581MedOct 6, 2025
    risk 0.28cvss 4.3epss 0.00

    When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.

  • CVE-2025-58589LowOct 6, 2025
    risk 0.18cvss 2.7epss 0.00

    When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.