CVE-2025-49183

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
12/06/2025
Last modified:
29/01/2026

Description

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:*