CVE-2025-27455

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:endress:meac300-fnade4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:endress:meac300-fnade4:-:*:*:*:*:*:*:*

History

06 Feb 2026, 14:39

Type Values Removed Values Added
CPE cpe:2.3:o:endress:meac300-fnade4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:endress:meac300-fnade4:-:*:*:*:*:*:*:*
First Time Endress
Endress meac300-fnade4 Firmware
Endress meac300-fnade4
Summary
  • (es) La aplicación web es vulnerable a ataques de clickjacking. El sitio puede estar incrustado en otro frame, lo que permite a un atacante engañar al usuario para que haga clic en algo distinto a lo que percibe, lo que podría revelar información confidencial o permitir que otros tomen el control de su ordenador mientras hacen clic en objetos aparentemente inofensivos.
References () https://sick.com/psirt - () https://sick.com/psirt - Vendor Advisory
References () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - () https://www.cisa.gov/resources-tools/resources/ics-recommended-practices - US Government Resource
References () https://www.endress.com - () https://www.endress.com - Product
References () https://www.first.org/cvss/calculator/3.1 - () https://www.first.org/cvss/calculator/3.1 - Not Applicable
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json - Vendor Advisory
References () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf - () https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf - Vendor Advisory

03 Jul 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-03 12:15

Updated : 2026-02-06 14:39


NVD link : CVE-2025-27455

Mitre link : CVE-2025-27455

CVE.ORG link : CVE-2025-27455


JSON object : View

Products Affected

endress

  • meac300-fnade4_firmware
  • meac300-fnade4
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames