SICK Enterprise and Logistic Analytics Products User Enumeration Vulnerability

Vulnerability

A vulnerability allowing user enumeration has been identified in SICK Enterprise Analytics and SICK Logistic Analytics products. This issue arises from a lack of authentication on certain endpoints, enabling unauthenticated users to request data and gather information about users. The vulnerability could potentially be exploited to bypass authentication and access sensitive information, as the application provides access to a login-protected H2 database for caching purposes, with usernames prefilled.

Impact

Exploitation of this vulnerability allows for user enumeration, where an attacker can gather information about existing usernames in the system. This could be further exploited to gain unauthorized access, especially in conjunction with other vulnerabilities that bypass authentication or expose sensitive information.

Remediation

Users are advised to ensure that only trusted entities have access to the affected SICK Enterprise Analytics and SICK Logistic Analytics products. Additionally, general security measures should be applied when operating these products. SICK's Operating Guidelines and ICS-CERT recommended practices on Industrial Security can provide further assistance in implementing these security practices.

Added: Oct 6, 2025, 7:19 AM
Updated: Oct 6, 2025, 7:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.