CVE-2025-54923
published 2025-08-20CVE-2025-54923: CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated…
PriorityP357high8.7CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.62%
45.9th percentile
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted deserialization payloads sent by authenticated users to network-exposed services in Schneider Electric EcoStruxure PME/EPO/PSO environments ↗
- →Monitor for malicious file uploads over HTTP by authenticated admin users that may exploit path traversal to achieve remote code execution (CVE-2025-54926, related context) ↗
- →Alert on outbound SSRF-style HTTP requests originating from EcoStruxure PME/EPO application servers, particularly triggered by specially crafted document submissions to vulnerable endpoints ↗
- →Monitor for path traversal patterns (e.g., ../ sequences) in authenticated HTTP requests processed by EcoStruxure PME/EPO/PSO, which may indicate exploitation of CVE-2025-54927 ↗
- ·CVE-2025-54923 (deserialization RCE) affects only EcoStruxure PME 2024 and 2024 R2; versions 2022, 2023, and 2023 R2 are NOT listed as affected for this specific CVE ↗
- ·Exploitation requires authenticated access (low privilege), making detection of anomalous authenticated sessions or credential abuse a relevant pre-exploitation signal ↗
- ·The Advanced Reporting and Dashboards Module (optional EPO 2022 component) installed alongside PME 2024 and 2024 R2 is also in scope for CVE-2025-54923 ↗
- ·Network segmentation is a key compensating control; EcoStruxure PME services should not be directly internet-exposed ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mxxc-fc9q-89hw: CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authent
ghsa_unreviewed·2025-08-20
CVE-2025-54923 [HIGH] CWE-502 GHSA-mxxc-fc9q-89hw: CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authent
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
CISA ICS
Schneider Electric EcoStruxure (Update B)
cisa_ics·2025-11-18·CVSS 7.5
[HIGH] Schneider Electric EcoStruxure (Update B)
ICS Advisory
##
Schneider Electric EcoStruxure (Update B)
Last RevisedNovember 18, 2025
Alert CodeICSA-25-224-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Power Monitoring Expert Software (PME), Power Operation (EPO), and Power SCADA Operation (PSO)
- Vulnerabilities: Deserialization of Untrusted Data, Server-Side Request Forgery (SSRF), Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow unauthorized access to sensitive data or remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneid
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-20
Published