PT-2025-6811 · Sick · Sick Meac300-Fnade4
Published
2025-02-14
·
Updated
2025-02-20
·
CVE-2025-0867
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SICK MEAC300-FNADE4 all versions
Description
The issue allows a standard user to execute commands with administrative privileges using the
run as function to start MEAC applications. This is possible because administrator credentials were stored to enable automatic system startup. As a result, the EPC2 user can perform privilege escalation to the administrative level.Recommendations
For SICK MEAC300-FNADE4 all versions, avoid storing administrator credentials for automatic system startup to prevent unauthorized privilege escalation in MEAC applications using the
run as function.Fix
LPE
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sick Meac300-Fnade4