Improper Privilege Management in Schneider Electric Products
CVE-2025-50124
7.2HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 July 2025
What is CVE-2025-50124?
A vulnerability exists in Schneider Electric products that allows for improper privilege management. This issue could lead to privilege escalation when a user accesses the server with a privileged account through a console. Exploitation can occur via a setup script, posing a risk to the integrity and security of the system. It is crucial for users to assess their configurations and apply necessary mitigations as outlined in the security notice.
Affected Version(s)
EcoStruxure™ IT Data Center Expert 8.3
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved