CVE-2025-49197
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/06/2025
Last modified:
26/01/2026
Description
The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sick:media_server:*:*:*:*:*:*:*:* | 1.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF
- https://sick.com/psirt
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf



