CVE-2025-41690 - CVE House
Back to Database
Status published High CVE-2025-41690

Endress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditions

Vulnerability Description

A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event log. This vulnerability could allow the Operator to authenticate as the Maintenance user, thereby gaining unauthorized access to sensitive configuration settings and the ability to modify device parameters.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41690

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Endress+Hauser

View all reports →

Affected Software

Promag 10 with HART, Promag 10 with IO-Link, Promag 10 with Modbus, Promass 10 with HART, Promass 10 with IO-Link, Promass 10 with Modbus
Vulnerable Versions:
0

Timeline

Official Publish: September 2nd, 2025
Last Modified: September 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)