CVE-2025-49199 PUBLISHED

Backup files can be modified and uploaded

Assigner: SICK AG
Reserved: 03.06.2025 Published: 12.06.2025 Updated: 17.06.2025

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor SICK AG
Product SICK Field Analytics
Versions Default: affected
  • Version all versions is affected

Workarounds

Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The collected resources \"SICK Operating Guidelines\" and \"ICS-CERT recommended practices on Industrial Security\" could help to implement the general security practices.

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE