Endress
Endress Meac300-fnade4 Firmware: vulnerabilidades y CVE
Endress Meac300-fnade4 Firmware tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27461 | Media (6.8) | 0.27% | — | 3 jul 2025 | During startup, the device automatically logs in the EPC2 Windows user without requesting a password. |
| CVE-2025-27460 | Media (6.8) | 0.13% | — | 3 jul 2025 | The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact… |
| CVE-2025-27459 | Alta (7.5) | 0.24% | — | 3 jul 2025 | The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered. |
| CVE-2025-27458 | Alta (7.5) | 0.21% | — | 3 jul 2025 | The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to the client, is encrypted by the client… |
| CVE-2025-27457 | Alta (7.5) | 0.29% | — | 3 jul 2025 | All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data. |
| CVE-2025-27456 | Crítica (9.8) | 0.60% | — | 3 jul 2025 | The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. |
| CVE-2025-27455 | Media (6.1) | 0.34% | — | 3 jul 2025 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus… |
| CVE-2025-27454 | Media (4.3) | 0.21% | — | 3 jul 2025 | The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did not intend. The request uses the victim's browser's saved… |
| CVE-2025-27453 | Media (6.5) | 0.43% | — | 3 jul 2025 | The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript. |
| CVE-2025-27452 | Alta (7.5) | 0.45% | — | 3 jul 2025 | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The… |
| CVE-2025-27451 | Media (5.3) | 0.43% | — | 3 jul 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until… |
| CVE-2025-27450 | Media (6.5) | 0.30% | — | 3 jul 2025 | The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the… |
| CVE-2025-27449 | Crítica (9.8) | 0.60% | — | 3 jul 2025 | The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. |
| CVE-2025-27448 | Media (5.4) | 0.32% | — | 3 jul 2025 | The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded. |
| CVE-2025-27447 | Media (6.1) | 0.35% | — | 3 jul 2025 | The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an… |
| CVE-2025-1711 | Alta (7.5) | 0.40% | — | 3 jul 2025 | Multiple services of the DUT as well as different scopes of the same service reuse the same credentials. |
| CVE-2025-1710 | Crítica (9.8) | 0.60% | — | 3 jul 2025 | The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. |
| CVE-2025-1709 | Media (6.5) | 0.42% | — | 3 jul 2025 | Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded). |
| CVE-2025-1708 | Alta (7.5) | 0.48% | — | 3 jul 2025 | The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.