CVE-2025-27457

MEDIUM

VNC - Info Disclosure

Title source: llm
STIX 2.1

Description

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
endress/meac300-fnade4_firmware
Published Jul 03, 2025
Tracked Since Feb 18, 2026