CVE-2025-27461
7.6Endress+Hauser · MEAC300-FNADE4
The Endress+Hauser MEAC300-FNADE4 device improperly enables an automatic login for the EPC2 Windows user during system startup, bypassing password requirements.
Executive summary
A critical authorization vulnerability in Endress+Hauser MEAC300-FNADE4 devices allows for unauthenticated access to the system during the startup phase.
Vulnerability
This vulnerability is a missing authorization flaw (CWE-862) where the device performs an automatic login of the EPC2 Windows user upon startup. The attack vector is physical (AV:P), as an actor requires local access to the device to exploit this startup behavior.
Business impact
Successful exploitation grants an attacker full access to the device environment, which can lead to complete compromise of the system, data loss, or operational disruption. Given the CVSS score of 7.6, this represents a significant risk to industrial control environments where physical security may be the primary barrier to unauthorized system interaction.
Remediation
Immediate Action: Contact Endress+Hauser support immediately to determine the availability of security updates or configuration changes required to disable the automatic login feature.
Proactive Monitoring: Monitor local access logs for unauthorized sessions or unexpected service activity originating from the EPC2 user account during startup events.
Compensating Controls: Implement strict physical access controls to the hardware to prevent unauthorized individuals from interacting with the device during the boot process.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability presents a substantial risk to the integrity of the affected hardware. Administrators must prioritize securing physical access to these devices and coordinate with the vendor to apply necessary updates or configuration hardening as soon as they become available.