CVE-2025-6788
published 2025-07-11CVE-2025-6788: A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other…
PriorityP429medium5.3CVSS 4.0
AVNACLATNPRLUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.27%
18.9th percentile
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources
to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML
diagrams.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider_electric | ecostruxure_power_monitoring_expert | >= 2023 < All | All |
| schneider_electric | ecostruxure_power_monitoring_expert | >= 2023 R2 < All | All |
| schneider_electric | ecostruxure_power_monitoring_expert | >= 2024 < All | All |
| schneider_electric | ecostruxure_power_monitoring_expert | >= 2024 R2 < All | All |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | >= 2022 w/ Advanced Reporting Module < All | All |
| schneider_electric | ecostruxure_power_operation_advanced_reporting_and_dashboards_module | >= 2024 w/ Advanced Reporting Module < All | All |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q2rf-262f-hfr2: CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources
to the wrong control sphere, providing other au
ghsa_unreviewed·2025-07-11
CVE-2025-6788 [MEDIUM] CWE-668 GHSA-q2rf-262f-hfr2: CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources
to the wrong control sphere, providing other au
CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources
to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML
diagrams.
CISA ICS
Schneider Electric EcoStruxure
cisa_ics·2025-07-22·CVSS 5.3
[MEDIUM] Schneider Electric EcoStruxure
ICS Advisory
##
Schneider Electric EcoStruxure
Release DateJuly 22, 2025
Alert CodeICSA-25-203-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 5.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: EcoStruxure Power Monitoring Expert (PME) and EcoStruxure Power Operation (EPO)
- Vulnerability: Exposure of Resource to Wrong Sphere
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could provide other authenticated users with potentially inappropriate access to TGML diagrams.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneider Electric reports the following products are affected:
- EcoStruxure Powe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-11
Published