CVE-2025-49183: Unencrypted communication (HTTP)
All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49183?
The severity of CVE-2025-49183 is rated as high with a score of 7.5.
What risks are associated with CVE-2025-49183?
CVE-2025-49183 poses risks including the potential interception of unencrypted traffic, allowing attackers to gather sensitive information.
How do I fix CVE-2025-49183?
To fix CVE-2025-49183, implement secure communication protocols such as HTTPS to encrypt traffic to the REST API.
Who is affected by CVE-2025-49183?
CVE-2025-49183 affects users of the SICK Media Server utilizing the REST API without encryption.
What kind of data can be exposed due to CVE-2025-49183?
Data exposed due to CVE-2025-49183 may include sensitive information and media files transferred over unencrypted HTTP.