CVE-2025-27459

MEDIUM

VNC - Info Disclosure

Title source: llm
STIX 2.1

Description

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.

Scores

CVSS v3 4.4
EPSS 0.0013
EPSS Percentile 31.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-257
Status published
Products (1)
endress/meac300-fnade4_firmware
Published Jul 03, 2025
Tracked Since Feb 18, 2026