Improper Privilege Management in Schneider Electric Products
CVE-2025-50124

7.2HIGH

What is CVE-2025-50124?

A vulnerability exists in Schneider Electric products that allows for improper privilege management. This issue could lead to privilege escalation when a user accesses the server with a privileged account through a console. Exploitation can occur via a setup script, posing a risk to the integrity and security of the system. It is crucial for users to assess their configurations and apply necessary mitigations as outlined in the security notice.

Affected Version(s)

EcoStruxure IT Data Center Expert Versions v8.3 and prior

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50124 : Improper Privilege Management in Schneider Electric Products