The vendor explicitly identifies these products as affected by this CVE.
- Endress+Hauser MEAC300-FNADE4 with Firmware <=0.16.0
- Summary
- The web application is susceptible to cross-site-scripting attacks. An attacker can create a prepared URL, which injects JavaScript code into the website. The code is executed in the victim’s browser when an authenticated administrator clicks the link.
- Remediation
- Customers are strongly advised to update to the newest version.
