SICK Field Analytics and Media Server Credentials Transmission Vulnerability

Vulnerability

A vulnerability exists in SICK Field Analytics and SICK Media Server versions through 1.4, where user credentials are sent as URL parameters instead of in the POST body. This flaw exposes sensitive information to unauthorized actors and could be exploited to modify application log file settings, potentially leading to a denial-of-service condition.

Impact

This vulnerability allows for the interception of user credentials, which could be exploited to gain unauthorized access to the application. Additionally, it could be used to disrupt application functionality by causing logged services to fail.

Remediation

Users of SICK Media Server are advised to upgrade to version 1.5 or later. For SICK Field Analytics, ensure that only trusted entities have access to the device and apply general security measures to operate the product in a protected IT environment.

Added: Jun 12, 2025, 2:57 PM
Updated: Jun 12, 2025, 2:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.