← Vulnerability feed

Vulnerability record · CVE-2020-2077 · published 29 July 2020

CVE-2020-2077: Sick package analytics incorrect default permissions vulnerability

Sick · Package Analytics

SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.

7.5 CVSS 3.1 High EPSS 1.0% · top 38.2% CWE-276 · Incorrect default permissions
7.5CVSS 3.1 base score, v2 5.0
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2077 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-58587Sick baggage analytics improper restriction of authentication attempts vulnerabilityThe application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possib…EPSS 0.49%9.8CVE-2020-2076Sick package analytics missing authentication for critical function vulnerabilitySICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST …EPSS 1.3%7.5CVE-2025-58591Sick baggage analytics path traversal vulnerabilityA remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerabl…EPSS 0.53%7.5CVE-2025-9914Sick baggage analytics authentication bypass via alternate path vulnerabilityThe credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorize…EPSS 0.32%7.5CVE-2025-58584Sick baggage analytics vulnerabilityIn the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such…EPSS 0.39%7.5CVE-2025-58585Sick baggage analytics vulnerabilityMultiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.EPSS 0.43%7.5CVE-2025-58590Sick baggage analytics path traversal vulnerabilityIt's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.EPSS 0.53%7.5CVE-2025-49184Sick baggage analytics information exposure vulnerabilityA remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the pro…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2020-2077), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.