Endress+Hauser MEAC300-FNADE4 Improper Restriction of Excessive Authentication Attempts Vulnerability

Vulnerability

A vulnerability exists in the Endress+Hauser MEAC300-FNADE4 product, all firmware versions, due to the SMB server's login mechanism. It fails to adequately prevent multiple failed authentication attempts within a short period, leaving the system open to brute-force attacks.

Impact

Exploitation of this vulnerability allows for brute-force attacks on the SMB server's login mechanism, potentially leading to unauthorized access.

Remediation

Users are strongly advised to update to the latest version of the MEAC300-FNADE4. General security practices should also be applied to minimize network exposure and restrict access to the device.

Added: Jul 3, 2025, 1:09 PM
Updated: Jul 3, 2025, 1:09 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.