CVE-2025-49186: Avaya Media Server

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Affected products

  • Avaya Media Server: affected versions not specified
  • Sick Baggage Analytics: any version
  • Sick Field Analytics: any version
  • Sick Logistic Diagnostic Analytics: any version
  • Sick Package Analytics: any version
  • Sick Tire Analytics: any version

Published 2025-06-12. Last modified 2026-06-17.