fkie_cve-2025-27452
Vulnerability from fkie_nvd
Published
2025-07-03 12:15
Modified
2025-07-03 15:13
Severity ?
Summary
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules
pose a risk to the webserver which enable dircetory listing.
References
Impacted products
Vendor | Product | Version |
---|
{ "cveTags": [], "descriptions": [ { "lang": "en", "value": "The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules \n\npose a risk to the webserver which enable dircetory listing." }, { "lang": "es", "value": "La configuraci\u00f3n del servidor web Apache httpd, que sirve a la aplicaci\u00f3n web MEAC300-FNADE4, es parcialmente insegura. Hay m\u00f3dulos activados que no son necesarios para el funcionamiento de la aplicaci\u00f3n web FNADE4. La funcionalidad de algunos m\u00f3dulos supone un riesgo para el servidor web que permite el listado de directorios." } ], "id": "CVE-2025-27452", "lastModified": "2025-07-03T15:13:53.147", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "psirt@sick.de", "type": "Secondary" } ] }, "published": "2025-07-03T12:15:23.100", "references": [ { "source": "psirt@sick.de", "url": "https://sick.com/psirt" }, { "source": "psirt@sick.de", "url": "https://sick.com/psirt" }, { "source": "psirt@sick.de", "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" }, { "source": "psirt@sick.de", "url": "https://www.endress.com" }, { "source": "psirt@sick.de", "url": "https://www.first.org/cvss/calculator/3.1" }, { "source": "psirt@sick.de", "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json" }, { "source": "psirt@sick.de", "url": "https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf" } ], "sourceIdentifier": "psirt@sick.de", "vulnStatus": "Awaiting Analysis", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-548" } ], "source": "psirt@sick.de", "type": "Secondary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…