CVE-2025-27447

The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the link.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:endress:meac300-fnade4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:endress:meac300-fnade4:-:*:*:*:*:*:*:*

History

06 Feb 2026, 14:38

Type Values Removed Values Added
Summary
  • (es) La aplicación web es susceptible a ataques de cross-site-scripting. Un atacante puede crear una URL preparada que inyecta código JavaScript en el sitio web. El código se ejecuta en el navegador de la víctima cuando un administrador autenticado hace clic en el enlace.
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.endress.com - () https://www.endress.com - Product
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf - Vendor Advisory
First Time Endress
Endress meac300-fnade4 Firmware
Endress meac300-fnade4
CPE cpe:2.3:o:endress:meac300-fnade4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:endress:meac300-fnade4:-:*:*:*:*:*:*:*

03 Jul 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-03 12:15

Updated : 2026-02-06 14:38


NVD link : CVE-2025-27447

Mitre link : CVE-2025-27447

CVE.ORG link : CVE-2025-27447


JSON object : View

Products Affected

endress

  • meac300-fnade4_firmware
  • meac300-fnade4
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')