PT-2025-40862 · Sick Ag+1 · Enterprise Analytics+1

Published

2025-10-06

·

Updated

2026-01-27

·

CVE-2025-58582

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Affected versions not specified
Description The system logs data from POST requests without validation. Specifically, when a user attempts to log in with incorrect credentials, the request data is logged. It is possible to send excessively large payloads in these requests, potentially impacting the system. The affected API endpoint is a login endpoint receiving POST requests. The vulnerable parameters include the data sent within the POST request, such as username and password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-58582

Affected Products

Enterprise Analytics
Sick