Sensitive Information Exposure in FTP Servers by Schneider Electric
CVE-2025-2002

4MEDIUM

What is CVE-2025-2002?

This vulnerability allows sensitive information, specifically FTP server credentials, to be inadvertently recorded in log files. When the FTP server is configured and runs in debug mode by an administrative user, and if these debug files are subsequently exported, the credentials may be disclosed. This situation poses a significant risk, especially in environments where sensitive data management is crucial.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

EcoStruxure Panel Server v2.0 and prior

References

CVSS V4

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.