SICK Enterprise and Logistic Analytics Products Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in SICK Enterprise Analytics and SICK Logistic Analytics products, all versions, allowing unauthorized access to sensitive information. This issue arises from improper authorization of configuration settings, which enables remote attackers to gather internal application data. Additionally, when errors occur, the application reveals full stack traces, including class and method names, which can be exploited to understand the application's structure and technology stack.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, including sensitive application data and internal error details that could aid in further attacks.

Remediation

Users are advised to ensure that only trusted entities have access to the device. It is also recommended to follow the SICK Operating Guidelines and the ICS-CERT recommended practices for Industrial Security to create a protected IT environment.

Added: Oct 6, 2025, 7:52 AM
Updated: Oct 6, 2025, 7:52 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.