Description
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.
Scores
CVSS v4
5.3
EPSS
0.0010
EPSS Percentile
27.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-668
Status
published
Products (6)
Schneider Electric/EcoStruxure™ Power Monitoring Expert
2023 - All
Schneider Electric/EcoStruxure™ Power Monitoring Expert
2023 R2 - All
Schneider Electric/EcoStruxure™ Power Monitoring Expert
2024 - All
Schneider Electric/EcoStruxure™ Power Monitoring Expert
2024 R2 - All
Schneider Electric/EcoStruxure™ Power Operation Advanced Reporting and Dashboards Module
2022 w/ Advanced Reporting Module - All
Schneider Electric/EcoStruxure™ Power Operation Advanced Reporting and Dashboards Module
2024 w/ Advanced Reporting Module - All
Published
Jul 11, 2025
Tracked Since
Feb 18, 2026