CVE-2025-27460

Published Jul 3, 2025

Last updated 4 months ago

Overview

Description
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows login. The attacker can read from and write to all files on the hard drives.
Source
psirt@sick.de
NVD status
Analyzed
Products
meac300-fnade4_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
6.8
Impact score
5.9
Exploitability score
0.9
Vector string
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

psirt@sick.de
CWE-312
nvd@nist.gov
CWE-326

Social media

Hype score
Not currently trending

Configurations