CVE-2025-8448
Published: Aug 20, 2025
Modified: Sep 9, 2025
Description
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.
| Vendor | Product | Versions |
|---|---|---|
Schneider Eelctric | EcoStruxure Building Operation Enterprise Server | affected All 7.x versions - < 7.0.2.348affected All 6.x versions - < 6.0.4.10001 (CP8)affected All 5.x versions - < 5.0.3.17009 (CP16) |
Schneider Electric | EcoStruxure Enterprise Server | affected All 7.x versions - < 7.0.2.348affected All 6.x versions - < 6.0.4.10001 (CP8)affected All 5.x versions - < 5.0.3.17009 (CP16) |
Schneider Eelctric | EcoStruxure Building Operation Workstation | affected All 7.x versions - < 7.0.2.348affected All 6.x versions - < 6.0.4.10001 (CP8)affected All 5.x versions - < 5.0.3.17009 (CP16) |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now