Vulnerabilities
Vulnerable Software
Endress:  >> Meac300-Fnade4 Firmware  Security Vulnerabilities
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-07-03
Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
CVSS Score
4.3
EPSS Score
0.002
Published
2025-07-03
The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the link.
CVSS Score
7.4
EPSS Score
0.001
Published
2025-07-03
The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.
CVSS Score
6.8
EPSS Score
0.001
Published
2025-07-03
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-07-03
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-07-03
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
CVSS Score
5.3
EPSS Score
0.002
Published
2025-07-03
The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.
CVSS Score
8.6
EPSS Score
0.001
Published
2025-07-03
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
CVSS Score
6.5
EPSS Score
0.001
Published
2025-07-03


Contact Us

Shodan ® - All rights reserved