CVE-2025-27449: Critical severity Endress Meac300-fnade4 Firmware vulnerability
Published Jul 3, 2025
·Updated
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
Affected Software
2 affected components
All of the following
Endress Meac300-fnade4 Firmware<=0.16.0
Endress Meac300-fnade4
Remediation
Information
Customers are strongly advised to update to the newest version.
Event History
Jul 3, 2025
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27449?
CVE-2025-27449 is rated as a medium severity vulnerability due to its potential for brute-force attack exploitation.
2
How do I fix CVE-2025-27449?
To mitigate CVE-2025-27449, implement account lockout mechanisms or increase delays between authentication attempts.
3
What systems are affected by CVE-2025-27449?
CVE-2025-27449 affects the Endress MEAC300-FNADE4 firmware versions up to and including 0.16.0.
4
Can CVE-2025-27449 be exploited remotely?
Yes, CVE-2025-27449 can potentially be exploited remotely by attackers attempting brute-force authentication.
5
What are the consequences of CVE-2025-27449 exploitation?
Exploitation of CVE-2025-27449 may allow unauthorized access to the device and its functionalities.