endress kayıtları
endress üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-307 Improper Restriction of Excessive Authentication Attempts3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1392 Use of Default Credentials1
- CWE-204 Observable Response Discrepancy1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-256 Plaintext Storage of a Password1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-6596İstismar yok | Endress+Hauser: Multiple products are vulnerable to code injectionendress · echo curve viewer · CWE-94 | Kritik9,8 | — | %0,8 | 10 Eyl 2024 |
39İzleyin | CVE-2025-27456İstismar yok | The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short tiendress · meac300-fnade4 firmware · CWE-307 | Kritik9,8 | — | %0,6 | 3 Tem 2025 |
39İzleyin | CVE-2025-1710İstismar yok | The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frendress · meac300-fnade4 firmware · CWE-307 | Kritik9,8 | — | %0,6 | 3 Tem 2025 |
39İzleyin | CVE-2025-27449İstismar yok | The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, makiendress · meac300-fnade4 firmware · CWE-307 | Kritik9,8 | — | %0,6 | 3 Tem 2025 |
35İzleyin | CVE-2020-12495İstismar yok | ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege managementendress · rsg35 firmware · CWE-269 | Yüksek8,8 | — | %0,9 | 19 Kas 2020 |
30İzleyin | CVE-2018-16059Kavram kanıtı | Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.endress · wirelesshart fieldgate swg70 firmware · CWE-22 | Orta5,3 | — | %29,8 | 7 Eyl 2018 |
30İzleyin | CVE-2025-1708İstismar yok | The application is vulnerable to SQL injection attacks.endress · meac300-fnade4 firmware · CWE-89 | Yüksek7,5 | — | %0,5 | 3 Tem 2025 |
30İzleyin | CVE-2025-27452İstismar yok | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.endress · meac300-fnade4 firmware · CWE-548 | Yüksek7,5 | — | %0,4 | 3 Tem 2025 |
30İzleyin | CVE-2025-1711İstismar yok | Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.endress · meac300-fnade4 firmware · CWE-1392 | Yüksek7,5 | — | %0,4 | 3 Tem 2025 |
30İzleyin | CVE-2025-27457İstismar yok | All communication between the VNC server and client(s) is unencrypted.endress · meac300-fnade4 firmware · CWE-319 | Yüksek7,5 | — | %0,3 | 3 Tem 2025 |
30İzleyin | CVE-2025-27459İstismar yok | The VNC application stores its passwords encrypted within the registry but uses DES for encryption.endress · meac300-fnade4 firmware · CWE-257 | Yüksek7,5 | — | %0,2 | 3 Tem 2025 |
30İzleyin | CVE-2025-27458İstismar yok | The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption.endress · meac300-fnade4 firmware · CWE-327 | Yüksek7,5 | — | %0,2 | 3 Tem 2025 |
27İzleyin | CVE-2025-27461İstismar yok | During startup, the device automatically logs in the EPC2 Windows user without requesting a password.endress · meac300-fnade4 firmware · CWE-862 | Orta6,8 | — | %0,2 | 3 Tem 2025 |
27İzleyin | CVE-2025-27460İstismar yok | The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker.endress · meac300-fnade4 firmware · CWE-312 | Orta6,8 | — | %0,1 | 3 Tem 2025 |
26İzleyin | CVE-2020-12496İstismar yok | ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actorendress · rsg35 firmware · CWE-200 | Orta6,5 | — | %0,8 | 19 Kas 2020 |
26İzleyin | CVE-2025-27453İstismar yok | The HttpOnly flag is set to false on the PHPSESSION cookie.endress · meac300-fnade4 firmware · CWE-1004 | Orta6,5 | — | %0,4 | 3 Tem 2025 |
26İzleyin | CVE-2025-1709İstismar yok | Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).endress · meac300-fnade4 firmware · CWE-256 | Orta6,5 | — | %0,4 | 3 Tem 2025 |
26İzleyin | CVE-2025-27450İstismar yok | The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.endress · meac300-fnade4 firmware · CWE-614 | Orta6,5 | — | %0,3 | 3 Tem 2025 |
24İzleyin | CVE-2025-27447İstismar yok | The web application is susceptible to cross-site-scripting attacks.endress · meac300-fnade4 firmware · CWE-79 | Orta6,1 | — | %0,3 | 3 Tem 2025 |
24İzleyin | CVE-2025-27455İstismar yok | The web application is vulnerable to clickjacking attacks.endress · meac300-fnade4 firmware · CWE-1021 | Orta6,1 | — | %0,3 | 3 Tem 2025 |
21İzleyin | CVE-2025-27451İstismar yok | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect passwoendress · meac300-fnade4 firmware · CWE-204 | Orta5,3 | — | %0,4 | 3 Tem 2025 |
21İzleyin | CVE-2025-27448İstismar yok | The web application is susceptible to cross-site-scripting attacks.endress · meac300-fnade4 firmware · CWE-79 | Orta5,4 | — | %0,3 | 3 Tem 2025 |
17İzleyin | CVE-2025-27454İstismar yok | The application is vulnerable to cross-site request forgery.endress · meac300-fnade4 firmware · CWE-352 | Orta4,3 | — | %0,2 | 3 Tem 2025 |
- CVE-2024-659639İzleyin
Endress+Hauser: Multiple products are vulnerable to code injection
KritikCVSS 9,8İstismar yokEPSS %1endress · echo curve viewer10 Eyl 2024
- CVE-2025-2745639İzleyin
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short ti
KritikCVSS 9,8İstismar yokEPSS %1endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-171039İzleyin
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time fr
KritikCVSS 9,8İstismar yokEPSS %1endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2744939İzleyin
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, maki
KritikCVSS 9,8İstismar yokEPSS %1endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2020-1249535İzleyin
ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 1.x has improper privilege management
YüksekCVSS 8,8İstismar yokEPSS %1endress · rsg35 firmware19 Kas 2020
- CVE-2018-1605930İzleyin
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
OrtaCVSS 5,3Kavram kanıtıEPSS %30endress · wirelesshart fieldgate swg70 firmware7 Eyl 2018
- CVE-2025-170830İzleyin
The application is vulnerable to SQL injection attacks.
YüksekCVSS 7,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745230İzleyin
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure.
YüksekCVSS 7,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-171130İzleyin
Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
YüksekCVSS 7,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745730İzleyin
All communication between the VNC server and client(s) is unencrypted.
YüksekCVSS 7,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745930İzleyin
The VNC application stores its passwords encrypted within the registry but uses DES for encryption.
YüksekCVSS 7,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745830İzleyin
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption.
YüksekCVSS 7,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2746127İzleyin
During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
OrtaCVSS 6,8İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2746027İzleyin
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker.
OrtaCVSS 6,8İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2020-1249626İzleyin
ENDRESS+HAUSER: Ecograph T utilizing Webserver firmware version 2.x exposures sensitive information to an unauthorized actor
OrtaCVSS 6,5İstismar yokEPSS %1endress · rsg35 firmware19 Kas 2020
- CVE-2025-2745326İzleyin
The HttpOnly flag is set to false on the PHPSESSION cookie.
OrtaCVSS 6,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-170926İzleyin
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
OrtaCVSS 6,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745026İzleyin
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.
OrtaCVSS 6,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2744724İzleyin
The web application is susceptible to cross-site-scripting attacks.
OrtaCVSS 6,1İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745524İzleyin
The web application is vulnerable to clickjacking attacks.
OrtaCVSS 6,1İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745121İzleyin
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect passwo
OrtaCVSS 5,3İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2744821İzleyin
The web application is susceptible to cross-site-scripting attacks.
OrtaCVSS 5,4İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2025-2745417İzleyin
The application is vulnerable to cross-site request forgery.
OrtaCVSS 4,3İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025