CVE-2025-49195: No protection against brute-force attacks
Published Jun 12, 2025
·Updated
The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.
Affected Software
1 affected component
SICK Media Server
Event History
Jun 12, 2025
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49195?
CVE-2025-49195 has a critical severity rating of 9.8.
2
How do I fix CVE-2025-49195?
To mitigate CVE-2025-49195, implement account lockout policies or restrict the number of authentication attempts on the FTP server.
3
What are the potential impacts of CVE-2025-49195?
CVE-2025-49195 could allow attackers to successfully brute-force user passwords, leading to unauthorized access to the FTP server.
4
Which software is affected by CVE-2025-49195?
CVE-2025-49195 affects the SICK Media Server, which has a vulnerable FTP login mechanism.
5
When was CVE-2025-49195 published?
CVE-2025-49195 was published on June 12, 2025.