VendorsSICKpackage_analyticsall versions
Vulnerabilities

SICK Package Analytics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2020-2076
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.
Published 2020-07-29 · Modified
9.8EPSS 0.013
CVE-2025-58587
Improper Restriction of Excessive Authentication Attempts
Published 2025-10-06 · Analyzed
9.8EPSS 0.005
CVE-2020-2077
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.
Published 2020-07-29 · Modified
7.5EPSS 0.010
CVE-2025-58590
Path traversal
Published 2025-10-06 · Analyzed
7.5EPSS 0.005
CVE-2025-58591
Path Traversal
Published 2025-10-06 · Analyzed
7.5EPSS 0.005
CVE-2025-49184
Information disclosure to unauthorized user
Published 2025-06-12 · Analyzed
7.5EPSS 0.005
CVE-2025-58585
Sensitive Information Disclosure Through Missing Authentication
Published 2025-10-06 · Analyzed
7.5EPSS 0.004
CVE-2025-58584
Plain Text Transmission of Username and Password in the URL
Published 2025-10-06 · Analyzed
7.5EPSS 0.004
CVE-2025-9914
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.
Published 2025-10-06 · Analyzed
7.5EPSS 0.003
CVE-2020-2078
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.
Published 2020-07-29 · Modified
6.5EPSS 0.008
CVE-2025-49186
No brute-force protection
Published 2025-06-12 · Analyzed
6.5EPSS 0.004
CVE-2025-58589
Information Disclosure Through Stacktrace
Published 2025-10-06 · Analyzed
6.5EPSS 0.004
CVE-2025-49193
Missing HTTP Security Headers
Published 2025-06-12 · Analyzed
6.1EPSS 0.003
CVE-2025-9913
Cross Site Scripting: Session Hijacking
Published 2025-10-06 · Analyzed
6.1EPSS 0.003
CVE-2025-58579
Username Disclosure Through Missing Authentication
Published 2025-10-06 · Analyzed
5.3EPSS 0.004
CVE-2025-58586
User Enumeration by excessive error output
Published 2025-10-06 · Analyzed
5.3EPSS 0.004