PT-2025-6811 · Sick · Sick Meac300-Fnade4

Published

2025-02-14

·

Updated

2025-02-20

·

CVE-2025-0867

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICK MEAC300-FNADE4 all versions
Description The issue allows a standard user to execute commands with administrative privileges using the run as function to start MEAC applications. This is possible because administrator credentials were stored to enable automatic system startup. As a result, the EPC2 user can perform privilege escalation to the administrative level.
Recommendations For SICK MEAC300-FNADE4 all versions, avoid storing administrator credentials for automatic system startup to prevent unauthorized privilege escalation in MEAC applications using the run as function.

Fix

LPE

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-01879
CVE-2025-0867

Affected Products

Sick Meac300-Fnade4