Path Traversal Vulnerability in Schneider Electric's Software
CVE-2025-54927
4.9MEDIUM
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-54927?
A path traversal vulnerability exists that may allow authenticated attackers to exploit improperly validated input to gain unauthorized access to sensitive files within the system. By crafting malicious path inputs, attackers can manipulate the filesystem structure, potentially leading to exposure of critical information and compromising system integrity. It is crucial for users and administrators of affected Schneider Electric software to apply necessary security patches and follow best practices to mitigate this vulnerability.
Affected Version(s)
EcoStruxure™ Power Monitoring Expert (PME) Version 2022
EcoStruxure™ Power Monitoring Expert (PME) Version 2023
EcoStruxure™ Power Monitoring Expert (PME) Version 2024