Endress

Meac300-fnade4 Firmware

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 03.07.2025 11:27:35
  • Zuletzt bearbeitet 06.02.2026 14:38:48

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

  • EPSS 0.03%
  • Veröffentlicht 03.07.2025 11:26:33
  • Zuletzt bearbeitet 06.02.2026 14:38:41

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

  • EPSS 0.15%
  • Veröffentlicht 03.07.2025 11:25:45
  • Zuletzt bearbeitet 06.02.2026 14:38:33

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • EPSS 0.06%
  • Veröffentlicht 03.07.2025 11:24:00
  • Zuletzt bearbeitet 06.02.2026 14:38:25

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.

  • EPSS 0.06%
  • Veröffentlicht 03.07.2025 11:23:20
  • Zuletzt bearbeitet 06.02.2026 14:38:12

The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the l...

  • EPSS 0.11%
  • Veröffentlicht 03.07.2025 11:22:09
  • Zuletzt bearbeitet 29.01.2026 18:59:16

Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

  • EPSS 0.15%
  • Veröffentlicht 03.07.2025 11:21:18
  • Zuletzt bearbeitet 06.02.2026 14:38:02

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • EPSS 0.08%
  • Veröffentlicht 03.07.2025 11:20:20
  • Zuletzt bearbeitet 06.02.2026 14:36:56

Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).

  • EPSS 0.08%
  • Veröffentlicht 03.07.2025 11:18:22
  • Zuletzt bearbeitet 29.01.2026 17:26:39

The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.