PT-2025-25325 · Sick Ag+1 · Sick Field Analytics+1

Published

2025-06-12

·

Updated

2026-01-26

·

CVE-2025-49199

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description The issue arises from unsigned backup ZIP files, which can be manipulated by attackers. This allows them to disrupt the application by configuring services in a way that they are unable to run, making the application unusable. Attackers can also redirect traffic meant to be internal to their own hosted services, gathering information in the process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2025-49199

Affected Products

Sick Field Analytics
Field Analytics