CVE-2025-41690: Endress+hauser Promag 10 With Hart
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event log. This vulnerability could allow the Operator to authenticate as the Maintenance user, thereby gaining unauthorized access to sensitive configuration settings and the ability to modify device parameters.
Affected products
- Endress+hauser Promag 10 With Hart: before 01.00.06 (fixed in 01.00.06)
- Endress+hauser Promag 10 With Io-Link: before 01.00.02 (fixed in 01.00.02)
- Endress+hauser Promag 10 With Modbus: before 01.00.06 (fixed in 01.00.06)
- Endress+hauser Promass 10 With Hart: before 01.00.06 (fixed in 01.00.06)
- Endress+hauser Promass 10 With Io-Link: before 01.00.02 (fixed in 01.00.02)
- Endress+hauser Promass 10 With Modbus: before 01.00.06 (fixed in 01.00.06)
Published 2025-09-02. Last modified 2026-06-17.