CVE-2025-27458
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-03

Last updated on: 2026-02-06

Assigner: SICK AG

Description
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to the client, is encrypted by the client and sent back. The server does the same encryption locally and if the responses match it is prooven that the client knows the correct password. Since all VNC communication is unencrypted, an attacker can obtain the challenge and response and try to derive the password from this information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-03
Last Modified
2026-02-06
Generated
2026-05-07
AI Q&A
2025-07-03
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
endress meac300-fnade4_firmware *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects the VNC authentication mechanism, which uses a challenge-response system where both server and client share the same password for encryption. The server sends a challenge to the client, which encrypts it and sends it back. The server then encrypts the challenge locally and compares the responses. Because all VNC communication is unencrypted, an attacker can intercept the challenge and response and attempt to derive the password from this information.


How can this vulnerability impact me? :

An attacker who intercepts the unencrypted VNC communication can obtain the challenge and response values and use them to try to derive the password. If successful, the attacker could gain unauthorized access to the VNC server, potentially compromising the confidentiality of the system without affecting integrity or availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart