The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules
pose a risk to the webserver which enable dircetory listing.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Meac300-fnade4_firmware | Endress | * | 0.16.0 (including) |