download.schneider-electric.com
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-03.pdf CVE-2025-0327
HIGH
Record summary
CVE-2025-0327 has a selected CVSS score of 8.5 (high).
Description
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
EcoStruxure Process ExpertBrowse Schneider Electric / EcoStruxure Process ExpertDefault status: unaffected | CVE List | Versions 2020R2 | affected |
| Versions 2021 & 2023 (prior to v4.8.0.5715) | affected | ||
EcoStruxure Process Expert for AVEVA System PlatformBrowse Schneider Electric / EcoStruxure Process Expert for AVEVA System PlatformDefault status: unaffected | CVE List | Versions 2020R2 | affected |
| Versions 2021 & 2023 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-0327