cbcvebase.
CVE-2025-54923
published 2025-08-20

CVE-2025-54923: CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated…

PriorityP357high8.7CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.62%
45.9th percentile
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.

Affected

6 ranges
VendorProductVersion rangeFixed in
schneider_electricecostruxure_power_monitoring_expert
schneider_electricecostruxure_power_monitoring_expert
schneider_electricecostruxure_power_monitoring_expert
schneider_electricecostruxure_power_monitoring_expert
schneider_electricecostruxure_power_operation_advanced_reporting_and_dashboards_module
schneider_electricecostruxure_power_operation_advanced_reporting_and_dashboards_module

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted deserialization payloads sent by authenticated users to network-exposed services in Schneider Electric EcoStruxure PME/EPO/PSO environments
  • Monitor for malicious file uploads over HTTP by authenticated admin users that may exploit path traversal to achieve remote code execution (CVE-2025-54926, related context)
  • Alert on outbound SSRF-style HTTP requests originating from EcoStruxure PME/EPO application servers, particularly triggered by specially crafted document submissions to vulnerable endpoints
  • Monitor for path traversal patterns (e.g., ../ sequences) in authenticated HTTP requests processed by EcoStruxure PME/EPO/PSO, which may indicate exploitation of CVE-2025-54927
  • ·CVE-2025-54923 (deserialization RCE) affects only EcoStruxure PME 2024 and 2024 R2; versions 2022, 2023, and 2023 R2 are NOT listed as affected for this specific CVE
  • ·Exploitation requires authenticated access (low privilege), making detection of anomalous authenticated sessions or credential abuse a relevant pre-exploitation signal
  • ·The Advanced Reporting and Dashboards Module (optional EPO 2022 component) installed alongside PME 2024 and 2024 R2 is also in scope for CVE-2025-54923
  • ·Network segmentation is a key compensating control; EcoStruxure PME services should not be directly internet-exposed
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.