Endress+Hauser MEAC300-FNADE4 Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting vulnerability has been identified in the Endress+Hauser MEAC300-FNADE4 web application, all firmware versions. This issue allows an authenticated administrator to inject JavaScript into the dashboard name, which is executed when the dashboard is loaded. The vulnerability arises because the application does not properly sanitize input before displaying it, creating an opportunity for script injection.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.

Remediation

Users are advised to update to the latest version of the MEAC300-FNADE4 firmware. Instructions for updating can be found on the Endress+Hauser website or by contacting Endress+Hauser support.

Added: Jul 3, 2025, 12:58 PM
Updated: Jul 3, 2025, 12:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.