Description
CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.
Scores
CVSS v3
7.8
EPSS
0.0021
EPSS Percentile
42.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-552
Status
published
Products (1)
Schneider Electric/ConneXium Network Manager
Version V2.0.01
Published
Apr 09, 2025
Tracked Since
Feb 18, 2026