CVE-2025-54927
published 2025-08-20CVE-2025-54927: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive…
PriorityP430medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.56%
42.6th percentile
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xg24-qhg2-gj63: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to se
ghsa_unreviewed·2025-08-20
CVE-2025-54927 [MEDIUM] CWE-22 GHSA-xg24-qhg2-gj63: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to se
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.
CISA ICS
Schneider Electric EcoStruxure (Update B)
cisa_ics·2025-11-18·CVSS 7.5
[HIGH] Schneider Electric EcoStruxure (Update B)
ICS Advisory
##
Schneider Electric EcoStruxure (Update B)
Last RevisedNovember 18, 2025
Alert CodeICSA-25-224-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Power Monitoring Expert Software (PME), Power Operation (EPO), and Power SCADA Operation (PSO)
- Vulnerabilities: Deserialization of Untrusted Data, Server-Side Request Forgery (SSRF), Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow unauthorized access to sensitive data or remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneid
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-20
Published