CVE-2025-27459

MEDIUM

Endress MEAC300-FNADE4 Firmware - Storing Passwords in a Recoverable Format via DES Encryption

Title source: llm
STIX 2.1

Description

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.

References (6)

Core 6
Core References
Vendor Advisory x_sick psirt security advisories
https://sick.com/psirt
Product x_endress+hauser
https://www.endress.com
US Government Resource x_ics-cert recommended practices on industrial security
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Not Applicable x_cvss v3.1 calculator
https://www.first.org/cvss/calculator/3.1

Scores

CVSS v3 4.4
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-257
Status published
Products (1)
endress/meac300-fnade4_firmware
Published Jul 03, 2025
Tracked Since Feb 18, 2026