« Volver al listado

CVE-2025-27450

Estado: AnalizadaMedia (6.5)—

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-27450",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-27450",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-03T13:05:28.775776Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@sick.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@sick.de",
      "affectedData": [
        {
          "vendor": "Endress+Hauser",
          "product": "Endress+Hauser MEAC300-FNADE4",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "<=0.16.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Endress+Hauser",
          "product": "Endress+Hauser MEAC300-FNADE4",
          "versions": [
            {
              "status": "unaffected",
              "version": ">=0.17.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-07-03T12:15:22.817",
  "references": [
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices",
      "tags": [
        "US Government Resource"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.endress.com",
      "tags": [
        "Product"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.first.org/cvss/calculator/3.1",
      "tags": [
        "Not Applicable"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@sick.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-614"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie."
    },
    {
      "lang": "es",
      "value": "El atributo Secure falta en varias cookies proporcionadas por MEAC300-FNADE4. Un atacante puede engañar a un usuario para que establezca una conexión HTTP sin cifrar con el servidor e interceptar la solicitud que contiene la cookie PHPSESSID."
    }
  ],
  "lastModified": "2026-06-17T09:03:36.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:endress:meac300-fnade4_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D360849D-4E70-4490-918C-9355B021CFD1",
              "versionEndIncluding": "0.16.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:endress:meac300-fnade4:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EDCFDEA0-D85E-464F-98FD-42775C42812F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@sick.de"
}