Insufficient Entropy Vulnerability in Schneider Electric Products
CVE-2025-50122
8.9HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 July 2025
What is CVE-2025-50122?
A vulnerability related to insufficient entropy has been identified in Schneider Electric products, which may allow for the potential discovery of root passwords. This issue arises when the algorithm used for password generation is susceptible to reverse engineering, especially if attackers gain access to installation or upgrade artifacts. Ensuring robust security practices and software updates can mitigate associated risks.
Affected Version(s)
EcoStruxure IT Data Center Expert Versions v8.3 and prior