Cross-site Scripting Vulnerability in Schneider Electric Products
CVE-2025-7746

5.3MEDIUM

What is CVE-2025-7746?

A Cross-site Scripting (XSS) vulnerability exists in certain Schneider Electric web applications due to improper neutralization of user input during page generation. This security flaw allows an attacker to inject unvalidated data into the web application, potentially enabling them to execute scripts in a victim's browser session. As a result, sensitive information may be accessed or modified without the user's consent, highlighting the importance of implementing strict input validation and sanitization measures.

Affected Version(s)

ATS490 Altivar Soft Starter all versions

ATV340E Altivar Machine Drives all versions

ATV6000 Medium Voltage Altivar Process Drives all versions

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.