Improper XML External Entity Reference Vulnerability in Schneider Electric's SOAP API
CVE-2025-6438

5.9MEDIUM

What is CVE-2025-6438?

A vulnerability exists in Schneider Electric's SOAP API that allows for the manipulation of API calls due to improper restrictions on XML external entities. This flaw can lead to unauthorized access to files on the server, particularly when accessed via the network using an application account. Attackers could exploit this weakness to inject malicious XML inputs, potentially compromising sensitive data and system integrity.

Affected Version(s)

EcoStruxure IT Data Center Expert Versions v8.3 and prior

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.