CNNVD-202510-835 Information

CNNVD ID

CNNVD-202510-835

CVE-2025-58591

  • CNNVD Published: 2025-10-06

Description (Chinese)

SICK AG Baggage Analytics是德国SICK AG公司的一款用于机场追踪系统的可视化和分析软件。 SICK AG Baggage Analytics存在安全漏洞,该漏洞源于远程未授权攻击者可暴力破解文件夹和文件并读取私钥或配置等敏感信息,可能导致敏感信息泄露。

Description (English)

SICK AG Baggage Analytics is a visualization and analysis software for airport tracking systems from SICK AG, Germany. SICK AG Baggage Analytics has a security loophole, which stems from the fact that remote, unauthorized assailants can violently decipher folders and documents and read sensitive information such as private keys or configurations, which can lead to the disclosure of sensitive information.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

SICK AG

Published

2025-10-06

Last Modified

2026-02-24

References

https://sick.com/psirt https://www.cisa.gov/resources-tools/resources/ics-recommended-practices https://www.first.org/cvss/calculator/3.1 https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf

Patch

https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt

Share on: