CVE-2025-0327
CVE-2025-0327
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 fev 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit
trail data and the other acting as server managing client request) that could cause a loss of Confidentiality,
Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the
executable path of the windows services. To be exploited, services need to be restarted.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Schneider Electric · EcoStruxure Process ExpertSchneider Electric · EcoStruxure Process Expert for AVEVA System PlatformQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →