Code Injection Vulnerability in Schneider Electric Products
CVE-2025-50123

7.2HIGH

What is CVE-2025-50123?

A code injection vulnerability has been identified that allows for remote command execution through improper handling of the hostname input. This security flaw can be exploited by an unauthorized user with privileged access when interacting with the affected Schneider Electric systems via a console interface. It is crucial for users to implement immediate security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

EcoStruxure IT Data Center Expert Versions v8.3 and prior

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50123 : Code Injection Vulnerability in Schneider Electric Products