Записи endress
23 опубликованных записей вендора endress.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-307 Improper Restriction of Excessive Authentication Attempts3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1392 Use of Default Credentials1
- CWE-204 Observable Response Discrepancy1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-6596Эксплойта нет | Endress+Hauser: Multiple products are vulnerable to code injectionendress · echo curve viewer · CWE-94 | Критическая9,8 | — | 0,8 % | 10 сент. 2024 г. |
39Наблюдать | CVE-2025-27456Эксплойта нет | The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short tiendress · meac300-fnade4 firmware · CWE-307 | Критическая9,8 | — | 0,6 % | 3 июл. 2025 г. |
39Наблюдать | CVE-2025-1710Эксплойта нет | The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frendress · meac300-fnade4 firmware · CWE-307 | Критическая9,8 | — | 0,6 % | 3 июл. 2025 г. |
39Наблюдать | CVE-2025-27449Эксплойта нет | The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, makiendress · meac300-fnade4 firmware · CWE-307 | Критическая9,8 | — | 0,6 % | 3 июл. 2025 г. |
35Наблюдать | CVE-2020-12495Эксплойта нет | ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege managementendress · rsg35 firmware · CWE-269 | Высокая8,8 | — | 0,9 % | 19 нояб. 2020 г. |
30Наблюдать | CVE-2018-16059Proof of concept | Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.endress · wirelesshart fieldgate swg70 firmware · CWE-22 | Средняя5,3 | — | 29,8 % | 7 сент. 2018 г. |
30Наблюдать | CVE-2025-1708Эксплойта нет | The application is vulnerable to SQL injection attacks.endress · meac300-fnade4 firmware · CWE-89 | Высокая7,5 | — | 0,5 % | 3 июл. 2025 г. |
30Наблюдать | CVE-2025-27452Эксплойта нет | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.endress · meac300-fnade4 firmware · CWE-548 | Высокая7,5 | — | 0,5 % | 3 июл. 2025 г. |
30Наблюдать | CVE-2025-1711Эксплойта нет | Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.endress · meac300-fnade4 firmware · CWE-1392 | Высокая7,5 | — | 0,4 % | 3 июл. 2025 г. |
30Наблюдать | CVE-2025-27457Эксплойта нет | All communication between the VNC server and client(s) is unencrypted.endress · meac300-fnade4 firmware · CWE-319 | Высокая7,5 | — | 0,3 % | 3 июл. 2025 г. |
30Наблюдать | CVE-2025-27459Эксплойта нет | The VNC application stores its passwords encrypted within the registry but uses DES for encryption.endress · meac300-fnade4 firmware · CWE-257 | Высокая7,5 | — | 0,2 % | 3 июл. 2025 г. |
30Наблюдать | CVE-2025-27458Эксплойта нет | The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption.endress · meac300-fnade4 firmware · CWE-327 | Высокая7,5 | — | 0,2 % | 3 июл. 2025 г. |
27Наблюдать | CVE-2025-27461Эксплойта нет | During startup, the device automatically logs in the EPC2 Windows user without requesting a password.endress · meac300-fnade4 firmware · CWE-862 | Средняя6,8 | — | 0,3 % | 3 июл. 2025 г. |
27Наблюдать | CVE-2025-27460Эксплойта нет | The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker.endress · meac300-fnade4 firmware · CWE-312 | Средняя6,8 | — | 0,1 % | 3 июл. 2025 г. |
26Наблюдать | CVE-2020-12496Эксплойта нет | ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actorendress · rsg35 firmware · CWE-200 | Средняя6,5 | — | 0,8 % | 19 нояб. 2020 г. |
26Наблюдать | CVE-2025-27453Эксплойта нет | The HttpOnly flag is set to false on the PHPSESSION cookie.endress · meac300-fnade4 firmware · CWE-1004 | Средняя6,5 | — | 0,4 % | 3 июл. 2025 г. |
26Наблюдать | CVE-2025-1709Эксплойта нет | Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).endress · meac300-fnade4 firmware · CWE-256 | Средняя6,5 | — | 0,4 % | 3 июл. 2025 г. |
26Наблюдать | CVE-2025-27450Эксплойта нет | The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.endress · meac300-fnade4 firmware · CWE-614 | Средняя6,5 | — | 0,3 % | 3 июл. 2025 г. |
24Наблюдать | CVE-2025-27447Эксплойта нет | The web application is susceptible to cross-site-scripting attacks.endress · meac300-fnade4 firmware · CWE-79 | Средняя6,1 | — | 0,3 % | 3 июл. 2025 г. |
24Наблюдать | CVE-2025-27455Эксплойта нет | The web application is vulnerable to clickjacking attacks.endress · meac300-fnade4 firmware · CWE-1021 | Средняя6,1 | — | 0,3 % | 3 июл. 2025 г. |
21Наблюдать | CVE-2025-27451Эксплойта нет | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect passwoendress · meac300-fnade4 firmware · CWE-204 | Средняя5,3 | — | 0,4 % | 3 июл. 2025 г. |
21Наблюдать | CVE-2025-27448Эксплойта нет | The web application is susceptible to cross-site-scripting attacks.endress · meac300-fnade4 firmware · CWE-79 | Средняя5,4 | — | 0,3 % | 3 июл. 2025 г. |
17Наблюдать | CVE-2025-27454Эксплойта нет | The application is vulnerable to cross-site request forgery.endress · meac300-fnade4 firmware · CWE-352 | Средняя4,3 | — | 0,2 % | 3 июл. 2025 г. |
- CVE-2024-659639Наблюдать
Endress+Hauser: Multiple products are vulnerable to code injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %endress · echo curve viewer10 сент. 2024 г.
- CVE-2025-2745639Наблюдать
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short ti
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-171039Наблюдать
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time fr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2744939Наблюдать
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, maki
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2020-1249535Наблюдать
ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege management
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %endress · rsg35 firmware19 нояб. 2020 г.
- CVE-2018-1605930Наблюдать
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
СредняяCVSS 5,3Proof of conceptEPSS 30 %endress · wirelesshart fieldgate swg70 firmware7 сент. 2018 г.
- CVE-2025-170830Наблюдать
The application is vulnerable to SQL injection attacks.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745230Наблюдать
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-171130Наблюдать
Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745730Наблюдать
All communication between the VNC server and client(s) is unencrypted.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745930Наблюдать
The VNC application stores its passwords encrypted within the registry but uses DES for encryption.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745830Наблюдать
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2746127Наблюдать
During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2746027Наблюдать
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2020-1249626Наблюдать
ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actor
СредняяCVSS 6,5Эксплойта нетEPSS 1 %endress · rsg35 firmware19 нояб. 2020 г.
- CVE-2025-2745326Наблюдать
The HttpOnly flag is set to false on the PHPSESSION cookie.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-170926Наблюдать
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
СредняяCVSS 6,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745026Наблюдать
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2744724Наблюдать
The web application is susceptible to cross-site-scripting attacks.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745524Наблюдать
The web application is vulnerable to clickjacking attacks.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745121Наблюдать
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect passwo
СредняяCVSS 5,3Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2744821Наблюдать
The web application is susceptible to cross-site-scripting attacks.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.
- CVE-2025-2745417Наблюдать
The application is vulnerable to cross-site request forgery.
СредняяCVSS 4,3Эксплойта нетEPSS 0 %endress · meac300-fnade4 firmware3 июл. 2025 г.