Account Name Change Vulnerability in SEL Software
CVE-2025-46740
7.5HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 12 May 2025
What is CVE-2025-46740?
A security flaw in Schneider Electric's SEL software enables an authenticated user without administrative privileges to modify the administrator account name. This vulnerability poses risks to system integrity and could lead to unauthorized changes, potentially compromising administrative controls. It is critical for users to ensure that only authorized personnel have access to sensitive account management functionalities.
Affected Version(s)
SEL Blueframe OS 0 < 1.12.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved