CVE-2025-27459
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.4epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
Endress+Hauser · Endress+Hauser MEAC300-FNADE4References
https://sick.com/psirthttps://www.cisa.gov/resources-tools/resources/ics-recommended-practiceshttps://www.endress.comhttps://www.first.org/cvss/calculator/3.1https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.jsonhttps://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf