Description
A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
Scores
CVSS v4
8.9
EPSS
0.0003
EPSS Percentile
8.6%
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-331
Status
published
Products (1)
Schneider Electric/EcoStruxure™ IT Data Center Expert
8.3 - Prior to
Published
Jul 11, 2025
Tracked Since
Feb 18, 2026