---
id: CVE-2025-58580
title: >-
  An API  endpoint  allows  arbitrary  log  entries  to  be  created  via  POST
  request
summary: >-
  An API  endpoint  allows  arbitrary  log  entries  to  be  created  via  POST
  request.  Without sufficient  validation  of the  input data, an attacker  can
  create manipulated log entries and thus falsify or dilute logs, for example.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-117
vendor: sick
product: enterprise_analytics
affected:
  - enterprise_analytics
published: '2025-10-06'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58580'
references:
  - url: 'https://sick.com/psirt'
    label: psirt@sick.de
  - url: 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices'
    label: psirt@sick.de
  - url: 'https://www.first.org/cvss/calculator/3.1'
    label: psirt@sick.de
  - url: 'https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.json'
    label: psirt@sick.de
  - url: 'https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0010.pdf'
    label: psirt@sick.de
  - url: >-
      https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
    label: psirt@sick.de
tags:
  - nvd
epss: 0.00365
epssPercentile: 0.283
ingestedAt: '2026-10-09T12:53:28.765Z'
---

## Overview

An API  endpoint  allows  arbitrary  log  entries  to  be  created  via  POST request.  Without sufficient  validation  of the  input data, an attacker  can create manipulated log entries and thus falsify or dilute logs, for example.

## Affected

- `enterprise_analytics`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
