CVE-2025-9914: CWE-288 Authentication Bypass Using an Alternate Path or Channel in SICK AG Baggage Analytics
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-9914) in SICK AG Baggage Analytics involves an authentication bypass due to the use of locally stored user credentials. An attacker with some level of access could leverage these credentials to bypass authentication controls and gain unauthorized access to the application. The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The CVSS 3.1 base score is 4.3, reflecting a network attack vector with low complexity, requiring low privileges and no user interaction, and impacting confidentiality only.
Potential Impact
An attacker exploiting this vulnerability could gain unauthorized access to the Baggage Analytics application, potentially exposing confidential information stored or processed by the system. There is no indication of impact on data integrity or system availability. The medium severity rating reflects the limited scope of impact focused on confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor SICK AG communications for updates. Until a fix is available, restrict access to the local database and ensure that credentials are protected with strong controls to reduce the risk of exploitation.
CVE-2025-9914: CWE-288 Authentication Bypass Using an Alternate Path or Channel in SICK AG Baggage Analytics
Description
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.
CVSS v3.1
Score 4.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-9914) in SICK AG Baggage Analytics involves an authentication bypass due to the use of locally stored user credentials. An attacker with some level of access could leverage these credentials to bypass authentication controls and gain unauthorized access to the application. The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The CVSS 3.1 base score is 4.3, reflecting a network attack vector with low complexity, requiring low privileges and no user interaction, and impacting confidentiality only.
Potential Impact
An attacker exploiting this vulnerability could gain unauthorized access to the Baggage Analytics application, potentially exposing confidential information stored or processed by the system. There is no indication of impact on data integrity or system availability. The medium severity rating reflects the limited scope of impact focused on confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor SICK AG communications for updates. Until a fix is available, restrict access to the local database and ensure that credentials are protected with strong controls to reduce the risk of exploitation.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- SICK AG
- Date Reserved
- 2025-09-03T08:59:00.184Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68e369cfbd6176610b49cab6
Added to database: 10/06/2025, 07:03:43 UTC
Last enriched: 05/14/2026, 02:30:29 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 241
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.