Path Traversal Vulnerability in Schneider Electric's Software
CVE-2025-54927

4.9MEDIUM

What is CVE-2025-54927?

A path traversal vulnerability exists that may allow authenticated attackers to exploit improperly validated input to gain unauthorized access to sensitive files within the system. By crafting malicious path inputs, attackers can manipulate the filesystem structure, potentially leading to exposure of critical information and compromising system integrity. It is crucial for users and administrators of affected Schneider Electric software to apply necessary security patches and follow best practices to mitigate this vulnerability.

Affected Version(s)

EcoStruxure™ Power Monitoring Expert (PME) Version 2022

EcoStruxure™ Power Monitoring Expert (PME) Version 2023

EcoStruxure™ Power Monitoring Expert (PME) Version 2024

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54927 : Path Traversal Vulnerability in Schneider Electric's Software