« Volver al listado

CVE-2025-49196

Estado: AnalizadaCrítica (9.1)—

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

TLS débil (CWE-327) permite interceptación de datos en tránsito (red sin privilegios, AV:N/AC:L/PR:N). Riesgo alto de exfiltración (C:H) y modificación de datos (I:H) mediante MITM.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-49196",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-49196",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-12T14:38:45.930361Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@sick.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@sick.de",
      "affectedData": [
        {
          "vendor": "SICK AG",
          "product": "SICK Field Analytics",
          "versions": [
            {
              "status": "affected",
              "version": "all versions",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-06-12T15:15:39.857",
  "references": [
    {
      "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF",
      "tags": [
        "Broken Link"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices",
      "tags": [
        "US Government Resource"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.first.org/cvss/calculator/3.1",
      "tags": [
        "Not Applicable"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@sick.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-327"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device."
    },
    {
      "lang": "es",
      "value": "Un servicio admite el uso de una versión de TLS obsoleta e insegura. Esto podría explotarse para exponer información confidencial, modificar datos de forma inesperada o suplantar la identidad de otros usuarios o dispositivos, lo que afectaría la confidencialidad e integridad del dispositivo."
    }
  ],
  "lastModified": "2026-06-17T09:30:54.960",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sick:field_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62EE84A7-E93D-411E-A6FC-4BEE5F4CD16D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@sick.de"
}