CVE-2025-58584
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1552.001Credentials In Filescredential access85 %
AV:N sin autenticación indica T1190. Las credenciales en URL se exponen pasivamente en logs/historial (T1552.001); CWE-598 sustenta divulgación de credenciales.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (5)
CWE
- CWE-598
Referencias
- https://sick.com/psirt
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf
- https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-58584",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-58584",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-10-06T16:37:16.225888Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@sick.de",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@sick.de",
"affectedData": [
{
"vendor": "SICK AG",
"product": "Baggage Analytics",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.6.3",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "Tire Analytics",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.6.3",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "Package Analytics",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.6.3",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "Logistic Diagnostic Analytics",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.6.3",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "Enterprise Analytics",
"versions": [
{
"status": "affected",
"version": "all versions",
"versionType": "custom"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-10-06T07:15:35.063",
"references": [
{
"url": "https://sick.com/psirt",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sick.de"
},
{
"url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices",
"tags": [
"US Government Resource"
],
"source": "psirt@sick.de"
},
{
"url": "https://www.first.org/cvss/calculator/3.1",
"tags": [
"Not Applicable"
],
"source": "psirt@sick.de"
},
{
"url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sick.de"
},
{
"url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sick.de"
},
{
"url": "https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf",
"tags": [
"Product"
],
"source": "psirt@sick.de"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@sick.de",
"description": [
{
"lang": "en",
"value": "CWE-598"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally."
}
],
"lastModified": "2026-06-17T09:44:34.377",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sick:baggage_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E62416BA-1BF1-43BD-98B2-57BD34128419"
},
{
"criteria": "cpe:2.3:a:sick:enterprise_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04E8EA78-2780-40C0-B5BA-6CF99DE6355B"
},
{
"criteria": "cpe:2.3:a:sick:logistic_diagnostic_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27031959-2981-4755-9E3D-02CD083F2B72"
},
{
"criteria": "cpe:2.3:a:sick:package_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5955214B-0D71-449A-BFD4-8804FDF91CA1"
},
{
"criteria": "cpe:2.3:a:sick:tire_analytics:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86C0BA69-E701-45A3-ADA5-130B8AD9DF15"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@sick.de"
}