CNNVD-202510-847 Information

CNNVD ID

CNNVD-202510-847

CVE-2025-58578

  • CNNVD Published: 2025-10-06

Description (Chinese)

SICK AG Enterprise Analytics是德国SICK AG公司的一个包裹分析软件。 SICK AG Enterprise Analytics存在安全漏洞,该漏洞源于缺少配额和检查机制,可能导致任意创建用户账户。

Description (English)

SICK AG Enterprise Analytics is a package analysis software for SICK AG in Germany. SICK AG Enterprise Analytics had a security loophole, which stemmed from the lack of quotas and check mechanisms, which could lead to the creation of user accounts at random.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

SICK AG

Published

2025-10-06

Last Modified

2026-02-24

References

https://sick.com/psirt https://www.first.org/cvss/calculator/3.1 https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf https://www.cisa.gov/resources-tools/resources/ics-recommended-practices https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf https://access.redhat.com/security/cve/cve-2025-58578

Patch

https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt

Share on: