Endress+Hauser MEAC300-FNADE4 Observable Response Discrepancy Vulnerability Allowing Username Enumeration
Vulnerability
A vulnerability exists in the Endress+Hauser MEAC300-FNADE4 application, all firmware versions, that allows an attacker to enumerate usernames. The application responds with different error messages for failed login attempts, indicating whether the failure was due to an incorrect password or a non-existent username. This discrepancy can be exploited to identify valid usernames.
Impact
Successful exploitation of this vulnerability could lead to unauthorized username enumeration, potentially allowing for further attacks such as password guessing or phishing.
Remediation
Users are advised to update the Endress+Hauser MEAC300-FNADE4 to the latest version. Instructions for updating can be found on the Endress+Hauser website or by contacting their customer support.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
