Known vulnerabilities in EcoStruxure Power Monitoring Expert 2024

Version: 2024
Software CPE: cpe:2.3:a:schneider_electric:ecostruxure_power_monitoring_expert:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting EcoStruxure Power Monitoring Expert version 2024 EcoStruxure Power Monitoring Expert 2024 is affected by 6 vulnerabilities: 4 medium, 2 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114977 - Server-Side Request Forgery (SSRF)
CVE-2025-54925
CWE-918 Medium
No
No
Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1 08.09.2025 SB20250908107
#VU114976 - Server-Side Request Forgery (SSRF)
CVE-2025-54924
CWE-918 Medium
No
No
Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1 08.09.2025 SB20250908107
#VU114975 - Deserialization of Untrusted Data
CVE-2025-54923
CWE-502 Medium
No
No
- 08.09.2025 SB20250908108
#VU114973 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-54927
CWE-22 Low
No
No
Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1 08.09.2025 SB20250908107
#VU114972 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-54926
CWE-22 Low
No
No
Hotfix_269476_Release_13.1, Hotfix_269509_Release_13.1 08.09.2025 SB20250908107
#VU113170 - Exposure of resource to wrong sphere
CVE-2025-6788
CWE-668 Medium
No
No
Hotfix_199767, Hotfix_256448 23.07.2025 SB2025072320