nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27450 CVE-2025-27450
MEDIUM
CVE-2025-27450
Record summary
CVE-2025-27450 has a selected CVSS score of 6.5 (medium).
Description
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 3, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Endress+Hauser MEAC300-FNADE4Browse Endress+Hauser / Endress+Hauser MEAC300-FNADE4Default status: unaffected, affected | CVE List | Through <=0.16.0 | affected |
| >=0.17.0 | unaffected |
References
7sick.comx_SICK PSIRT Security Advisories
https://sick.com/psirt cisa.govx_ICS CERT recommended practices on Industrial Security
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices endress.comx_Endress+Hauser
https://www.endress.com/ first.orgx_CVSS v3.1 Calculator
https://www.first.org/cvss/calculator/3.1 sick.comx_The canonical URL.
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json sick.comVendor advisory
https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf