Vendor CVEs
SICK AG
All CVEs
155 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-32471 | Low | 0.24 | 3.7 | 0.00 | Apr 28, 2025 | The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks. | ||
| CVE-2025-49198 | Low | 0.20 | 3.1 | 0.00 | Jun 12, 2025 | The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens. | ||
| CVE-2025-58589 | Low | 0.18 | 2.7 | 0.00 | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. | ||
| CVE-2026-11841 | Cri | 0.00 | 9.4 | 0.00 | Jul 28, 2026 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature,… | ||
| CVE-2026-22920 | 0.00 | — | 0.00 | Jan 15, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
- risk 0.24cvss 3.7epss 0.00
The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.
- risk 0.20cvss 3.1epss 0.00
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
- risk 0.18cvss 2.7epss 0.00
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.
- risk 0.00cvss 9.4epss 0.00
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature,…
- CVE-2026-22920Jan 15, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Page 4 of 4