PT-2025-6811 · Sick · Sick Meac300-Fnade4

CVE-2025-0867

·

Published

2025-02-14

·

Updated

2025-02-20

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICK MEAC300-FNADE4 all versions
Description The issue allows a standard user to execute commands with administrative privileges using the run as function to start MEAC applications. This is possible because administrator credentials were stored to enable automatic system startup. As a result, the EPC2 user can perform privilege escalation to the administrative level.
Recommendations For SICK MEAC300-FNADE4 all versions, avoid storing administrator credentials for automatic system startup to prevent unauthorized privilege escalation in MEAC applications using the run as function.

Fix

LPE

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01879
CVE-2025-0867

Affected Products

Sick Meac300-Fnade4