Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Endress

First CVE: Sep 7, 2018Active for: 8 yearsTotal CVEs: 23
29.4
VTI Score
Low

Endress manufactures industrial automation and process-measurement equipment, with a compact but strategically important product portfolio in the process-control and field-device domain. Its vulnerabilities skew toward serious outcomes, with an elevated tendency toward critical severity, concentrating in control devices such as the MEAC300 series and affecting a relatively narrow but prominent segment of industrial infrastructure. The recurring weaknesses—improper authentication limits, cross-site scripting, cleartext credential storage and transmission, and cross-site request forgery—reflect the legacy design patterns and minimal security-by-default posture common to older industrial control hardware and firmware, where network isolation was once assumed and cryptographic transport was deferred or omitted. These classes matter significantly to defenders because they are endemic to direct-attached and remote-management interfaces on field devices, where remediation often requires firmware patching or operational constraints rather than simple configuration; industrial environments should inventory affected device types and assess exposure through both firmware version and network positioning. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Endress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Jul 3, 2025
386 days ago

Products(22 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-16059MEDIUM
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
Sep 7, 20185.354NOYES
CVE-2024-6596CRITICAL
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
Sep 10, 20249.828NONO
CVE-2025-27456CRITICAL
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute
Jul 3, 20259.826NONO
CVE-2020-12495HIGH
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-bas
Nov 19, 20208.826NONO
CVE-2025-27449CRITICAL
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks
Jul 3, 20259.825NONO
CVE-2025-1710CRITICAL
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-forc
Jul 3, 20259.825NONO
CVE-2025-1708HIGH
The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content.
Jul 3, 20257.522NONO
CVE-2025-27459HIGH
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
Jul 3, 20257.521NONO
CVE-2025-27458HIGH
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to th
Jul 3, 20257.521NONO
CVE-2025-1709MEDIUM
Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded).
Jul 3, 20256.521NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
52%
30%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (91.3%)
Unknown0 (0.0%)
Physical2 (8.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (73.9%)
Unknown0 (0.0%)
Required6 (26.1%)
Privileges Required
Low4 (17.4%)
High0 (0.0%)
None19 (82.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 95th percentile
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Endress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Endress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Endress's Products

View all 3 CNAs →

Top CWEs