Home

Description

Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

PUBLISHED Reserved 2026-01-08 | Published 2026-01-15 | Updated 2026-01-15 | Assigner SICK AG




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-598 Use of GET Request Method With Sensitive Query Strings

Product status

Default status
affected

all versions (custom)
affected

References

sick.com/psirt

www.sick.com/...lines_cybersecurity_by_sick_en_im0106719.pdf

www.cisa.gov/...es-tools/resources/ics-recommended-practices

www.first.org/cvss/calculator/3.1

www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.json

www.sick.com/.well-known/csaf/white/2026/sca-2026-0002.pdf vendor-advisory

cve.org (CVE-2026-22644)

nvd.nist.gov (CVE-2026-22644)

Download JSON