Endress+Hauser MEAC300-FNADE4 Observable Response Discrepancy Vulnerability Allowing Username Enumeration

Vulnerability

A vulnerability exists in the Endress+Hauser MEAC300-FNADE4 application, all firmware versions, that allows an attacker to enumerate usernames. The application responds with different error messages for failed login attempts, indicating whether the failure was due to an incorrect password or a non-existent username. This discrepancy can be exploited to identify valid usernames.

Impact

Successful exploitation of this vulnerability could lead to unauthorized username enumeration, potentially allowing for further attacks such as password guessing or phishing.

Remediation

Users are advised to update the Endress+Hauser MEAC300-FNADE4 to the latest version. Instructions for updating can be found on the Endress+Hauser website or by contacting their customer support.

Added: Jul 3, 2025, 1:36 PM
Updated: Jul 3, 2025, 1:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.