← Vulnerability feed

Vulnerability record · CVE-2025-49193 · published 12 June 2025

CVE-2025-49193: Sick baggage analytics vulnerability

Sick · Baggage Analytics

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

6.1 CVSS 3.1 Medium EPSS 0.31% · top 78.4% CWE-693 · CWE-693
6.1CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49193 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-58587Sick baggage analytics improper restriction of authentication attempts vulnerabilityThe application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possib…EPSS 0.49%9.8CVE-2025-49199Sick field analytics insufficient verification of data authenticity vulnerabilityThe backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. Th…EPSS 0.33%9.8CVE-2025-49195Sick media server improper restriction of authentication attempts vulnerabilityThe FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compro…EPSS 0.52%9.8CVE-2025-49182Sick media server vulnerabilityFiles in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full acces…EPSS 0.55%9.8CVE-2020-2076Sick package analytics missing authentication for critical function vulnerabilitySICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST …EPSS 1.3%9.1CVE-2025-49196Sick field analytics broken cryptographic algorithm vulnerabilityA service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected…EPSS 0.26%8.6CVE-2025-49181Sick media server missing authorization vulnerabilityDue to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could als…EPSS 0.40%7.5CVE-2025-58591Sick baggage analytics path traversal vulnerabilityA remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerabl…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2025-49193), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.