CVE-2025-27456: Critical severity Endress Meac300-fnade4 Firmware vulnerability
Published Jul 3, 2025
·Updated
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
Affected Software
2 affected components
All of the following
Endress Meac300-fnade4 Firmware
Endress Meac300-fnade4
Event History
Jul 3, 2025
CVE Published
via MITRE·11:32 AM
Data Sourced
via MITRE·11:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
May 23, 58071
Event
via NVD·11:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-27456?
CVE-2025-27456 has been classified as a high-severity vulnerability due to its potential for exploitation via brute-force attacks.
2
How do I fix CVE-2025-27456?
To mitigate CVE-2025-27456, implement account lockout mechanisms and rate limiting on failed authentication attempts.
3
What systems are affected by CVE-2025-27456?
CVE-2025-27456 primarily affects the Endress Meac300-fnade4 Firmware.
4
What type of attack does CVE-2025-27456 enable?
CVE-2025-27456 enables brute-force attacks by allowing multiple failed login attempts within a short timeframe.
5
Are there any known exploits for CVE-2025-27456?
As of now, there are no known exploits publicly available for CVE-2025-27456.