Sensitive Information Exposure in FTP Servers by Schneider Electric
CVE-2025-2002

4MEDIUM

Key Information:

Vendor
CVE Published:
12 March 2025

Summary

This vulnerability allows sensitive information, specifically FTP server credentials, to be inadvertently recorded in log files. When the FTP server is configured and runs in debug mode by an administrative user, and if these debug files are subsequently exported, the credentials may be disclosed. This situation poses a significant risk, especially in environments where sensitive data management is crucial.

Affected Version(s)

EcoStruxure Panel Server v2.0 and prior

References

CVSS V4

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.