PT-2025-25308 · Sick Ag+1 · Sick Media Server+1

Published

2025-06-12

·

Updated

2026-01-29

·

CVE-2025-49183

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description The issue is related to unencrypted communication with the REST API, which uses HTTP. This allows an attacker to intercept traffic between the actor and the webserver, potentially leading to information gathering and downloading media files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-49183

Affected Products

Sick Media Server
Mediaserver