CVE Database
/

CVE-2025-8448

Back to search

CVE-2025-8448

Published: Aug 20, 2025

Modified: Sep 9, 2025

PUBLISHED

Description

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.

VendorProductVersions

Schneider Eelctric

EcoStruxure Building Operation Enterprise Server

affected
All 7.x versions - < 7.0.2.348
affected
All 6.x versions - < 6.0.4.10001 (CP8)
affected
All 5.x versions - < 5.0.3.17009 (CP16)

Schneider Electric

EcoStruxure Enterprise Server

affected
All 7.x versions - < 7.0.2.348
affected
All 6.x versions - < 6.0.4.10001 (CP8)
affected
All 5.x versions - < 5.0.3.17009 (CP16)

Schneider Eelctric

EcoStruxure Building Operation Workstation

affected
All 7.x versions - < 7.0.2.348
affected
All 6.x versions - < 6.0.4.10001 (CP8)
affected
All 5.x versions - < 5.0.3.17009 (CP16)

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now