ZeroHour

CVE-2025-27450

CVSS 3.1
6.5 medium
EPSS
<1%p18
Published
()
Modified
Description

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.

Vendors
endress
Products
meac300-fnade4 firmware
Weakness
CWE-614
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.