CVE-2025-49186

T

he product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:avaya:media_server:-:*:*:*:*:*:*:*
cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:*

History

03 Feb 2026, 14:39

Type Values Removed Values Added
First Time Sick package Analytics
Sick logistic Diagnostic Analytics
Avaya media Server
Sick tire Analytics
Sick field Analytics
Avaya
Sick
Sick baggage Analytics
References () https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF - () https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF - Broken Link
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf - Vendor Advisory
Summary
  • (es) El producto no implementa medidas suficientes para evitar múltiples intentos fallidos de autenticación en un corto período de tiempo, lo que lo hace susceptible a ataques de fuerza bruta.
CPE cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:avaya:media_server:-:*:*:*:*:*:*:*
cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:*

13 Jun 2025, 09:15

Type Values Removed Values Added
CWE CWE-79 CWE-307

12 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 14:15

Updated : 2026-02-03 14:39


NVD link : CVE-2025-49186

Mitre link : CVE-2025-49186

CVE.ORG link : CVE-2025-49186


JSON object : View

CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts