CVE-2025-49186: Avaya Media Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
Affected products
- Avaya Media Server: affected versions not specified
- Sick Baggage Analytics: any version
- Sick Field Analytics: any version
- Sick Logistic Diagnostic Analytics: any version
- Sick Package Analytics: any version
- Sick Tire Analytics: any version
Published 2025-06-12. Last modified 2026-06-17.