Vulnerability Description
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sick | Field Analytics | All versions |
Related Weaknesses (CWE)
References
- https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SIBroken Link
- https://sick.com/psirtVendor Advisory
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practicesUS Government Resource
- https://www.first.org/cvss/calculator/3.1Not Applicable
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.jsonVendor Advisory
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0007.pdfVendor Advisory
FAQ
What is CVE-2025-49191?
CVE-2025-49191 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the das...
How severe is CVE-2025-49191?
CVE-2025-49191 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-49191?
Check the references section above for vendor advisories and patch information. Affected products include: Sick Field Analytics.