Endress+Hauser MEAC300-FNADE4 VNC Authentication Vulnerability Allowing Password Derivation
Vulnerability
A vulnerability exists in the VNC authentication mechanism of the Endress+Hauser MEAC300-FNADE4 device, all firmware versions. The issue arises because the VNC communication is unencrypted, allowing an attacker to intercept the challenge-response data used for authentication. This interception can be exploited to derive the password used for VNC encryption, potentially leading to unauthorized access.
Impact
Exploitation of this vulnerability could allow a remote, unauthenticated attacker to intercept VNC authentication data and derive the password used for encryption, potentially leading to unauthorized access to the VNC server.
Remediation
Users are strongly advised to update the Endress+Hauser MEAC300-FNADE4 to the latest version. General security practices should also be applied to minimize network exposure and restrict access to the device.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
