The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules

pose a risk to the webserver which enable dircetory listing.
Fixes

Solution

Customers are strongly advised to update to the newest version.


Workaround

No workaround given by the vendor.

History

Thu, 03 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Jul 2025 11:45:00 +0000

Type Values Removed Values Added
Description The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the webserver which enable dircetory listing.
Title CVE-2025-27452
Weaknesses CWE-548
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2025-07-03T13:16:16.586Z

Reserved: 2025-02-26T08:39:58.980Z

Link: CVE-2025-27452

cve-icon Vulnrichment

Updated: 2025-07-03T13:13:41.382Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-03T12:15:23.100

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-27452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.