Sensitive Information Exposure in FTP Servers by Schneider Electric
CVE-2025-2002
4MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Status
- Vendor
- CVE Published:
- 12 March 2025
Summary
This vulnerability allows sensitive information, specifically FTP server credentials, to be inadvertently recorded in log files. When the FTP server is configured and runs in debug mode by an administrative user, and if these debug files are subsequently exported, the credentials may be disclosed. This situation poses a significant risk, especially in environments where sensitive data management is crucial.
Affected Version(s)
EcoStruxure Panel Server v2.0 and prior
References
CVSS V4
Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved