CVE-2025-54924

7.5

Schneider Electric · EcoStruxure Power Monitoring Expert and EcoStruxure Power Operation

A Server-Side Request Forgery (SSRF) vulnerability allows unauthenticated attackers to access sensitive data by sending a specially crafted document to a vulnerable endpoint.

Executive summary

Schneider Electric EcoStruxure platforms are vulnerable to an unauthenticated SSRF attack that could lead to the unauthorized exposure of sensitive internal data.

Vulnerability

This is a Server-Side Request Forgery (CWE-918) vulnerability triggered by sending a malicious document to an endpoint. The CVSS vector indicates that the attack is network-based, requires no authentication, and involves no user interaction.

Business impact

The ability for an unauthenticated attacker to perform SSRF poses a significant risk to the confidentiality of internal network resources. With a CVSS score of 7.5, this vulnerability could allow an attacker to bypass perimeter defenses to query internal services, potentially exposing sensitive configuration data or credentials stored within the Schneider Electric environment.

Remediation

Immediate Action: Consult the official Schneider Electric security notice (SEVD-2025-224-02) to identify and apply the necessary patches or configuration changes provided by the vendor.

Proactive Monitoring: Review web server and application access logs for unusual requests containing document file paths or unexpected external URL parameters.

Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect incoming document uploads and block requests that attempt to target internal network addresses or sensitive local files.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

Given the unauthenticated nature of this vulnerability and the potential for unauthorized data access, organizations running the affected Schneider Electric software must prioritize this assessment. Administrators should verify their current version against the vendor advisory and apply all provided security updates to eliminate the SSRF vector immediately.

More Schneider Electric CVEs

Sources