CVE detail
CVE-2025-27456
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Vendor Advisorywww.sick.comJul 3, 2025, 12:15 PMNo excerpt available.
Vendor Advisorywww.sick.comJul 3, 2025, 12:15 PM- https://www.first.org/cvss/calculator/3.1www.first.org
No excerpt available.
Not Applicablewww.first.orgJul 3, 2025, 12:15 PM - https://www.endress.comwww.endress.com
No excerpt available.
referencewww.endress.comJul 3, 2025, 12:15 PM No excerpt available.
Mitigationwww.cisa.govJul 3, 2025, 12:15 PM- https://sick.com/psirtsick.com
No excerpt available.
Vendor Advisorysick.comJul 3, 2025, 12:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-27449CVSS 7.5 · High
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attack…
- CVE-2025-1710CVSS 7.5 · High
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-for…
- CVE-2025-27461CVSS 7.6 · High
During startup, the device automatically logs in the EPC2 Windows user without requesting a password.
- CVE-2025-27460CVSS 7.6 · High
The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alte…
- CVE-2025-27459CVSS 4.4 · Medium
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
- CVE-2025-27458CVSS 6.5 · Medium
The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to t…