Account Name Change Vulnerability in SEL Software
CVE-2025-46740

7.5HIGH

Key Information:

Vendor
CVE Published:
12 May 2025

What is CVE-2025-46740?

A security flaw in Schneider Electric's SEL software enables an authenticated user without administrative privileges to modify the administrator account name. This vulnerability poses risks to system integrity and could lead to unauthorized changes, potentially compromising administrative controls. It is critical for users to ensure that only authorized personnel have access to sensitive account management functionalities.

Affected Version(s)

SEL Blueframe OS 0 < 1.12.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.