Перейти к содержимому
Noroxi

Записи endress

23 опубликованных записей вендора endress.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

23 записей
  • CVE-2024-6596
    39Наблюдать

    Endress+Hauser: Multiple products are vulnerable to code injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    endress · echo curve viewer10 сент. 2024 г.

  • CVE-2025-27456
    39Наблюдать

    The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short ti

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-1710
    39Наблюдать

    The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time fr

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27449
    39Наблюдать

    The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, maki

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2020-12495
    35Наблюдать

    ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege management

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    endress · rsg35 firmware19 нояб. 2020 г.

  • CVE-2018-16059
    30Наблюдать

    Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.

    СредняяCVSS 5,3Proof of conceptEPSS 30 %

    endress · wirelesshart fieldgate swg70 firmware7 сент. 2018 г.

  • CVE-2025-1708
    30Наблюдать

    The application is vulnerable to SQL injection attacks.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27452
    30Наблюдать

    The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-1711
    30Наблюдать

    Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27457
    30Наблюдать

    All communication between the VNC server and client(s) is unencrypted.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27459
    30Наблюдать

    The VNC application stores its passwords encrypted within the registry but uses DES for encryption.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27458
    30Наблюдать

    The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27461
    27Наблюдать

    During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27460
    27Наблюдать

    The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker.

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2020-12496
    26Наблюдать

    ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actor

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    endress · rsg35 firmware19 нояб. 2020 г.

  • CVE-2025-27453
    26Наблюдать

    The HttpOnly flag is set to false on the PHPSESSION cookie.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-1709
    26Наблюдать

    Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27450
    26Наблюдать

    The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27447
    24Наблюдать

    The web application is susceptible to cross-site-scripting attacks.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27455
    24Наблюдать

    The web application is vulnerable to clickjacking attacks.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27451
    21Наблюдать

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect passwo

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27448
    21Наблюдать

    The web application is susceptible to cross-site-scripting attacks.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.

  • CVE-2025-27454
    17Наблюдать

    The application is vulnerable to cross-site request forgery.

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    endress · meac300-fnade4 firmware3 июл. 2025 г.