Insufficient Entropy Vulnerability in Schneider Electric Products
CVE-2025-50122

8.9HIGH

What is CVE-2025-50122?

A vulnerability related to insufficient entropy has been identified in Schneider Electric products, which may allow for the potential discovery of root passwords. This issue arises when the algorithm used for password generation is susceptible to reverse engineering, especially if attackers gain access to installation or upgrade artifacts. Ensuring robust security practices and software updates can mitigate associated risks.

Affected Version(s)

EcoStruxure IT Data Center Expert Versions v8.3 and prior

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.