{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-27455","assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","state":"PUBLISHED","assignerShortName":"SICK AG","dateReserved":"2025-02-26T08:39:58.980Z","datePublished":"2025-07-03T11:30:49.265Z","dateUpdated":"2025-07-03T13:15:59.115Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Endress+Hauser MEAC300-FNADE4","vendor":"Endress+Hauser","versions":[{"lessThanOrEqual":"<=0.16.0","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"affected","product":"Endress+Hauser MEAC300-FNADE4","vendor":"Endress+Hauser","versions":[{"status":"unaffected","version":">=0.17.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects.</p>"}],"value":"The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives, thus potentially revealing confidential information or allowing others to take control of their computer while clicking on seemingly innocuous objects."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","environmentalScore":4.3,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":4.3,"temporalSeverity":"MEDIUM","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1021","description":"CWE-1021 Improper Restriction of Rendered UI Layers or Frames","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG","dateUpdated":"2025-07-03T11:30:49.265Z"},"references":[{"tags":["x_Endress+Hauser"],"url":"https://www.endress.com"},{"tags":["x_SICK PSIRT Security Advisories"],"url":"https://sick.com/psirt"},{"tags":["x_ICS-CERT recommended practices on Industrial Security"],"url":"https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"},{"tags":["x_CVSS v3.1 Calculator"],"url":"https://www.first.org/cvss/calculator/3.1"},{"tags":["x_The canonical URL."],"url":"https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json"},{"tags":["vendor-advisory"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory"],"url":"https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Customers are strongly advised to update to the newest version.</p>"}],"value":"Customers are strongly advised to update to the newest version."}],"source":{"advisory":"SCA-2025-0008","discovery":"INTERNAL"},"title":"CVE-2025-27455","x_generator":{"engine":"csaf2cve 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-07-03T12:59:47.844638Z","id":"CVE-2025-27455","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-07-03T13:15:59.115Z"}}]}}