VYPR

MEAC300-FNADE4

by SICK AG

CVEs (3)

  • CVE-2025-27449HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.01

    The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • CVE-2025-27450MedJul 3, 2025
    risk 0.42cvss 6.5epss 0.00

    The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

  • CVE-2025-27452MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the…