CVE-2025-58581
⚪ Do wiadomości
Ujawnienie pełnego śladu stosu w aplikacji umożliwia atakującemu poznanie technologii i struktury aplikacji.
CVSS
4.3
EPSS
0.3%
Exploit
none
Vendor
sick
Opis źródłowy (NVD)
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-10-06 07:15:34 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 10:10:00 UTC |
Referencje
- https://sick.com/psirt ([email protected]) [Vendor Advisory]
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices ([email protected]) [US Government Resource]
- https://www.first.org/cvss/calculator/3.1 ([email protected]) [Not Applicable]
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json ([email protected]) [Vendor Advisory]
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf ([email protected]) [Vendor Advisory]
- https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf ([email protected]) [Product]