CVE-2025-58580
Last modified
CVE-2025-58580 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sick | Enterprise Analytics | All versions |
References
- https://sick.com/psirtVendor Advisory
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practicesUS Government Resource
- https://www.first.org/cvss/calculator/3.1Not Applicable
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-58580?
How severe is CVE-2025-58580?
How do I fix CVE-2025-58580?
Are you affected by CVE-2025-58580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
