Exposure of Resource to Wrong Sphere in EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module and EcoStruxure Power Monitoring Expert - CVE-2025-6788
Published: July 23, 2025
Vulnerability identifier: #VU113170
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-6788
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to exposure of resource to wrong sphere. A remote user can gain unauthorized access to TGML diagrams.
Affected software
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
EcoStruxure Power Monitoring Expert
EcoStruxure Power Monitoring Expert
How to mitigate CVE-2025-6788
Install updates from vendor's website.
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module - addressed in versions Hotfix_199767, Hotfix_256448
EcoStruxure Power Monitoring Expert - addressed in versions Hotfix_199767, Hotfix_256448
EcoStruxure Power Monitoring Expert - addressed in versions Hotfix_199767, Hotfix_256448