Security
Headlines
HeadlinesLatestCVEs

Headline

Schneider Electric EcoStruxture IT Data Center Expert

View CSAF

  1. EXECUTIVE SUMMARY CVSS v4 9.5 ATTENTION: Exploitable remotely/low attack complexity Vendor: Schneider Electric Equipment: EcoStruxure IT Data Center Expert Vulnerabilities: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’), Insufficient Entropy, Improper Control of Generation of Code (‘Code Injection’), Server-Side Request Forgery (SSRF), Improper Privilege Management, and Improper Restriction of XML External Entity Reference
  2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to disrupt operations and access system data.
  3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS Schneider Electric reports the following product is affected: EcoStruxure IT Data Center Expert: Versions v8.3 and prior 3.2 Vulnerability Overview 3.2.1 IMPROPER NEUTRALIZATION OF SPECIAL ELEMENTS USED IN AN OS COMMAND (‘OS COMMAND INJECTION’) CWE-78 An improper neutralization of special elements used in an OS command (‘OS command injection’) vulnerability exists, which could cause unauthenticated remote code execution when a malicious folder is created via the HTTP web interface when enabled. HTTP is disabled by default. CVE-2025-50121 has been assigned to this vulnerability. A CVSS v3.1 base score of 10.0 has been calculated; the CVSS vector string is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). A CVSS v4 score has also been calculated for CVE-2025-50121. A base score of 9.5 has been calculated; the CVSS vector string is (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H). 3.2.2 INSUFFICIENT ENTROPY CWE-331 An insufficient entropy vulnerability exists, which could cause the root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts. CVE-2025-50122 has been assigned to this vulnerability. A CVSS v3.1 base score of 8.3 has been calculated; the CVSS vector string is (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). A CVSS v4 score has also been calculated for CVE-2025-50122. A base score of 8.9 has been calculated; the CVSS vector string is (CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H). 3.2.3 IMPROPER CONTROL OF GENERATION OF CODE (‘CODE INJECTION’) CWE-94 An improper control of generation of code (‘code injection’) vulnerability exists, which could cause remote command execution by a privileged account when the server is accessed via a console and the hostname input is exploited. CVE-2025-50123 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.2 has been calculated; the CVSS vector string is (CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). A CVSS v4 score has also been calculated for CVE-2025-50123. A base score of 7.2 has been calculated; the CVSS vector string is (CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H). 3.2.4 SERVER-SIDE REQUEST FORGERY (SSRF) CWE-918 A server-side request forgery (SSRF) vulnerability exists, which could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of the host request header. CVE-2025-50125 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.2 has been calculated; the CVSS vector string is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N). A CVSS v4 score has also been calculated for CVE-2025-50125. A base score of 6.3 has been calculated; the CVSS vector string is (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N). 3.2.5 IMPROPER PRIVILEGE MANAGEMENT CWE-269 An improper privilege management vulnerability exists, which could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation of a setup script. CVE-2025-50124 has been assigned to this vulnerability. A CVSS v3.1 base score of 6.9 has been calculated; the CVSS vector string is (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). A CVSS v4 score has also been calculated for CVE-2025-50124. A base score of 7.2 has been calculated; the CVSS vector string is (CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H). 3.2.6 IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611 An improper restriction of XML external entity reference vulnerability exists, which could cause manipulation of SOAP API calls and XML external entities injection, resulting in unauthorized file access when the server is accessed via the network using an application account. CVE-2025-6438 has been assigned to this vulnerability. A CVSS v3.1 base score of 6.8 has been calculated; the CVSS vector string is (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). A CVSS v4 score has also been calculated for CVE-2025-6438. A base score of 5.9 has been calculated; the CVSS vector string is (CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N). 3.3 BACKGROUND CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing COUNTRIES/AREAS DEPLOYED: Worldwide COMPANY HEADQUARTERS LOCATION: France 3.4 RESEARCHER Jaggar Henry and Jim Becher of KoreLogic, Inc. reported these vulnerabilities to Schneider Electric.
  4. MITIGATIONS Schneider Electric has identified the following specific workarounds and mitigations users can apply to reduce risk: Schneider Electric EcoStruxure IT Data Center Expert Version 8.3 and prior: Version 9.0 of EcoStruxure IT Data Center Expert includes fixes for these vulnerabilities and is available upon request from Schneider Electric’s Customer Care Center. If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:

Harden the DCE instance according to the cybersecurity best practices documented in the EcoStruxure IT Data Center Expert Security Handbook For more information see the associated Schneider Electric CPCERT security advisory SEVD-2025-189-01 EcoStruxure IT Data Center Expert - SEVD-2025-189-01 PDF Version, EcoStruxure IT Data Center Expert - SEVD-2025-189-01 CSAF Version. CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

  1. UPDATE HISTORY July 22, 2025: Initial Republication of Schneider Electric CPCERT SEVD-2025-189-01
us-cert
#vulnerability#web#rce#ssrf#pdf#auth

us-cert: Latest News

Lantronix Provisioning Manager