Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-27459

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be r…

Mitigation only
Fix from $1,950 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.8
CVE-2025-27460

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical acces…

Mitigation only
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.8
CVE-2025-27461

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

Mitigation only
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware CRITICAL 9.8
CVE-2025-27456

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame,…

Mitigation only
Fix from $2,300 2025-07-03
Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-27452

The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that…

Fix: after 0.16.0
Fix from $1,950 2025-07-03
Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-27457

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

Mitigation only
Fix from $1,950 2025-07-03
Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-27458

The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challeng…

Mitigation only
Fix from $1,950 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.5
CVE-2025-27453

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.1
CVE-2025-27455

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into cli…

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware CRITICAL 9.8
CVE-2025-1710

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, maki…

Fix: after 0.16.0
Fix from $2,300 2025-07-03
Meac300 Fnade4 Firmware CRITICAL 9.8
CVE-2025-27449

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it sus…

Fix: after 0.16.0
Fix from $2,300 2025-07-03
Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-1711

Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

Fix: after 0.16.0
Fix from $1,950 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.5
CVE-2025-27450

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP con…

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.1
CVE-2025-27447

The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the web…

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 5.4
CVE-2025-27448

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the das…

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 5.3
CVE-2025-27451

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a n…

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Meac300 Fnade4 Firmware HIGH 7.5
CVE-2025-1708

The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.

Fix: after 0.16.0
Fix from $1,950 2025-07-03
Meac300 Fnade4 Firmware MEDIUM 6.5
CVE-2025-1709

Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).

Fix: after 0.16.0
Fix from $1,600 2025-07-03
Echo Curve Viewer CRITICAL 9.8
CVE-2024-6596

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

Fix: 1.40.1 / 6.0.0+
Fix from $2,300 2024-09-10
Rsg35 Firmware HIGH 8.8
CVE-2020-12495

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. Th…

Fix: 2.0.0+
Fix from $1,950 2020-11-19
Rsg35 Firmware MEDIUM 6.5
CVE-2020-12496

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.…

Fix: 2.0.0+
Fix from $1,600 2020-11-19
Wirelesshart Fieldgate Swg70 Firmware MEDIUM 5.3
CVE-2018-16059EPSS 30%

Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.

No fix yet
Fix from $1,600 2018-09-07