Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Endress

66 known vulnerabilities

2
CRITICAL
7
HIGH
14
MEDIUM

Top Products

meac300-fnade4 firmware 19 meac300-fnade4 19 rsg35 firmware 2 rsg35 2 rsg45 firmware 2 rsg45 2 orsg35 firmware 2 orsg35 2 orsg45 firmware 2 orsg45 2
23 CVEs
7.6
CVE-2025-27461

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

7.6
CVE-2025-27460

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an

4.4
CVE-2025-27459

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, th

6.5
CVE-2025-27458

The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password

6.5
CVE-2025-27457

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic

7.5
CVE-2025-27456

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp

4.3
CVE-2025-27455

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta

4.3
CVE-2025-27454

The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitti

5.3
CVE-2025-27453

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such

5.3
CVE-2025-27452

The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. The

5.3
CVE-2025-27451

For failed login attempts, the application returns different error messages depending on whether the login failed due to

6.5
CVE-2025-27450

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to esta

7.5
CVE-2025-27449

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh

6.8
CVE-2025-27448

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject

7.4
CVE-2025-27447

The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects

4.3
CVE-2025-1711

Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.

7.5
CVE-2025-1710

The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi

6.5
CVE-2025-1709

Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).

8.6
CVE-2025-1708

The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its

9.8
CVE-2024-6596

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users c

6.5
CVE-2020-12496

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45

9.1
CVE-2020-12495

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to impr

5.3
CVE-2018-16059

Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par

Frequently Asked Questions

How many CVEs affect Endress?

Endress has 66 CVE records in our database, including 18 critical and 14 high severity vulnerabilities.

What are the most severe Endress vulnerabilities?

Endress has 18 critical severity (CVSS 9.0+) and 14 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Endress vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Endress products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Endress Vulnerabilities

CyberStrike scans your infrastructure for Endress vulnerabilities and provides real-time remediation guidance.

Get Started