6.5

CVE-2025-27450

CVE-2025-27450

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EndressMeac300-fnade4 Firmware Version <= 0.16.0
   EndressMeac300-fnade4 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.157
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@sick.de 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.

https://sick.com/psirt
Vendor Advisory
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
US Government Resource
https://www.first.org/cvss/calculator/3.1
Not Applicable
https://www.endress.com
Product
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json
Vendor Advisory
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf
Vendor Advisory