Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26393 | A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event log. This vulnerability could allow the Operator to authenticate as the Maintenance user, thereby gaining unauthorized access to sensitive configuration settings and the ability to modify device parameters. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-068 |
|
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Endress+hauser
Endress+hauser proline 10 |
|
| Vendors & Products |
Endress+hauser
Endress+hauser proline 10 |
Tue, 02 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event log. This vulnerability could allow the Operator to authenticate as the Maintenance user, thereby gaining unauthorized access to sensitive configuration settings and the ability to modify device parameters. | |
| Title | Endress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditions | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-09-02T13:48:59.186Z
Reserved: 2025-04-16T11:17:48.309Z
Link: CVE-2025-41690
Updated: 2025-09-02T13:48:56.755Z
Status : Awaiting Analysis
Published: 2025-09-02T08:15:30.583
Modified: 2025-09-02T15:55:25.420
Link: CVE-2025-41690
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:02Z
EUVD