CNNVD-202509-204 Information

CNNVD ID

CNNVD-202509-204

CVE-2025-41690

  • CNNVD Published: 2025-09-02

Description (Chinese)

Endress+hauser Ecograph是瑞士Endress+hauser公司的一个数据记录仪。用于安全、完整地记录和​​可视化所有过程序列。 Endress+hauser Ecograph存在日志信息泄露漏洞,该漏洞源于密码泄露,可能导致低权限用户通过查看事件日志获取高权限用户密码。

Description (English)

Endess+hauser Ecograph is a data recorder for Enders+hauser in Switzerland. For the safe and complete recording and visualization of all process sequences. Endress+hauser Ecograph has a leak in log information, which originates from a password leak, which may lead low-permissible users to obtain high-permit user passwords by viewing event logs.

Hazard Level

Medium

Vulnerability Type

日志信息泄露

Affected Vendor

Endress+Hauser

Published

2025-09-02

Last Modified

2026-02-24

References

https://certvde.com/en/advisories/VDE-2025-068 https://nvd.nist.gov/vuln/detail/CVE-2025-41690 https://access.redhat.com/security/cve/cve-2025-41690

Patch

https://www.us.endress.com/en/field-instruments-overview/flow-measurement-product-overview/electromagnetic-flowmeter-promag-10p?srsltid=AfmBOooo_tRlgdhY5-GEGJE5_WKpJkPY3-f30e4TDM4Jli-3KkAdiY7W&t.tabId=product-downloads

Share on: