CVE-2025-58581
MEDIUMSICK Enterprise Analytics - Exposure of Sensitive Information via Error Stacktrace
Title source: llmDescription
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
References (6)
Core 6
Core References
Vendor Advisory x_sick psirt security advisories
https://sick.com/psirt
Product x_sick operating guidelines
https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
US Government Resource x_ics-cert recommended practices on industrial security
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Not Applicable x_cvss v3.1 calculator
https://www.first.org/cvss/calculator/3.1
Vendor Advisory x_the canonical url.
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json
Vendor Advisory vendor-advisory
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf
Scores
CVSS v3
4.3
EPSS
0.0030
EPSS Percentile
21.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
sick/enterprise_analytics
Published
Oct 06, 2025
Tracked Since
Feb 18, 2026