CVE-2025-49197 PUBLISHED

Deprecated TLS version supported

Assigner: SICK AG
Reserved: 03.06.2025 Published: 12.06.2025 Updated: 17.06.2025

The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor SICK AG
Product SICK Media Server
Versions Default: unaffected
  • affected from 0 to 1.5 (excl.)

Solutions

It is strongly recommended to upgrade to the latest version.

References

Problem Types

  • CWE-328 Use of Weak Hash CWE