Endress manufactures industrial automation and process-measurement equipment, with a compact but strategically important product portfolio in the process-control and field-device domain. Its vulnerabilities skew toward serious outcomes, with an elevated tendency toward critical severity, concentrating in control devices such as the MEAC300 series and affecting a relatively narrow but prominent segment of industrial infrastructure. The recurring weaknesses—improper authentication limits, cross-site scripting, cleartext credential storage and transmission, and cross-site request forgery—reflect the legacy design patterns and minimal security-by-default posture common to older industrial control hardware and firmware, where network isolation was once assumed and cryptographic transport was deferred or omitted. These classes matter significantly to defenders because they are endemic to direct-attached and remote-management interfaces on field devices, where remediation often requires firmware patching or operational constraints rather than simple configuration; industrial environments should inventory affected device types and assess exposure through both firmware version and network positioning. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Endress over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16059MEDIUM Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. | Sep 7, 2018 | 5.3 | 54 | NO | YES |
CVE-2024-6596CRITICAL An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | Sep 10, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-27456CRITICAL The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute | Jul 3, 2025 | 9.8 | 26 | NO | NO |
CVE-2020-12495HIGH Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-bas | Nov 19, 2020 | 8.8 | 26 | NO | NO |
CVE-2025-27449CRITICAL The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks | Jul 3, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-1710CRITICAL The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-forc | Jul 3, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-1708HIGH The application is vulnerable to SQL injection attacks. An attacker is able to dump the PostgreSQL database and read its content. | Jul 3, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-27459HIGH The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered. | Jul 3, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-27458HIGH The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to th | Jul 3, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-1709MEDIUM Several credentials for the local PostgreSQL database are stored in plain text (partially base64 encoded). | Jul 3, 2025 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Endress.
Media articles that mention a CVE ID that affects a product developed by Endress — matched by CVE ID, not by vendor name.