Endress+Hauser MEAC300-FNADE4 Improper Restriction of Excessive Authentication Attempts Vulnerability
Vulnerability
A vulnerability exists in the Endress+Hauser MEAC300-FNADE4 product, all firmware versions, due to the SMB server's login mechanism. It fails to adequately prevent multiple failed authentication attempts within a short period, leaving the system open to brute-force attacks.
Impact
Exploitation of this vulnerability allows for brute-force attacks on the SMB server's login mechanism, potentially leading to unauthorized access.
Remediation
Users are strongly advised to update to the latest version of the MEAC300-FNADE4. General security practices should also be applied to minimize network exposure and restrict access to the device.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
