CVE-2025-49187: User enumeration
Published Jun 12, 2025
·Updated
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
Affected Software
1 affected component
SICK Field Analytics
Event History
Jun 12, 2025
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49187?
The severity of CVE-2025-49187 is rated medium with a score of 5.3.
2
How do I fix CVE-2025-49187?
To fix CVE-2025-49187, implement consistent error messages for failed login attempts to prevent user enumeration.
3
What software is affected by CVE-2025-49187?
CVE-2025-49187 affects SICK Field Analytics.
4
What type of vulnerability is CVE-2025-49187?
CVE-2025-49187 is a user enumeration vulnerability that allows attackers to discover valid usernames.
5
When was CVE-2025-49187 published?
CVE-2025-49187 was published on June 12, 2025.