CVE-2025-58584
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/10/2025
Last modified:
27/01/2026
Description
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sick:enterprise_analytics:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://sick.com/psirt
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf
- https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf



