CVE-2025-27450
—CVSS 3.1
6.5 medium
EPSS
<1%p18
Published
()
Modified
Description
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to the server and intercept the request containing the PHPSESSID cookie.
- Vendors
- endress
- Products
- meac300-fnade4 firmware
- Weakness
- CWE-614
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.