Insufficient Entropy in EcoStruxure IT Data Center Expert - CVE-2025-50122
Published: July 14, 2025
Vulnerability identifier: #VU112877
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-50122
CWE-ID: CWE-331
Exploitation vector: Adjecent network
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient entropy issue. A remote attacker on the local network can cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
Affected software
EcoStruxure IT Data Center Expert
How to mitigate CVE-2025-50122
Install updates from vendor's website.
EcoStruxure IT Data Center Expert - update to 9.0