CVE-2025-49196

MEDIUM

SICK Field Analytics - Use of a Broken or Risky Cryptographic Algorithm

Title source: llm
STIX 2.1

Description

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device.

References (6)

Core 6
Core References
Vendor Advisory x_sick psirt website
https://sick.com/psirt
US Government Resource x_ics-cert recommended practices on industrial security
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Not Applicable x_cvss v3.1 calculator
https://www.first.org/cvss/calculator/3.1

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-327
Status published
Products (1)
sick/field_analytics
Published Jun 12, 2025
Tracked Since Feb 18, 2026