ZeroHour

CVE-2025-58586

CVSS 3.1
5.3 medium
EPSS
<1%p30
Published
()
Modified
Description

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

Vendors
sick
Products
baggage analytics, enterprise analytics, logistic diagnostic analytics, package analytics, tire analytics
Weakness
CWE-204
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.