The vendor explicitly identifies these products as affected by this CVE.
- Endress+Hauser MEAC300-FNADE4 with Firmware <=0.16.0
- Summary
- For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
- Remediation
- Customers are strongly advised to update to the newest version.
