Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32503 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. |
Solution
No solution given by the vendor.
Workaround
Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The collected resources ”SICK Operating Guidelines” and ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.
Thu, 29 Jan 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sick
Sick baggage Analytics Sick logistic Diagnostic Analytics Sick package Analytics Sick tire Analytics |
|
| CPEs | cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sick
Sick baggage Analytics Sick logistic Diagnostic Analytics Sick package Analytics Sick tire Analytics |
Mon, 06 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Oct 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. | |
| Title | Cross Site Scripting: Session Hijacking | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2025-10-06T12:23:05.532Z
Reserved: 2025-09-03T08:58:58.185Z
Link: CVE-2025-9913
Updated: 2025-10-06T12:23:01.998Z
Status : Analyzed
Published: 2025-10-06T07:15:36.200
Modified: 2026-01-29T01:55:44.377
Link: CVE-2025-9913
No data.
OpenCVE Enrichment
No data.
EUVD