ZeroHour

CVE-2025-49183

CVSS 3.1
7.5 high
EPSS
<1%p21
Published
()
Modified
Description

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

Vendors
sick
Products
media server
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.