Impact
The vulnerability is an insufficiently protected credentials flaw that allows a local privileged attacker to bypass authentication and alter stored credentials within the EcoStruxure Cybersecurity Admin Expert application. This flaw could enable the attacker to assume higher privileges, gain control over managed devices, and potentially carry out further malicious operations. The weakness is classified as CWE‑522.
Affected Systems
Schneider Electric EcoStruxure Cybersecurity Admin Expert is affected. No specific product versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local privileged user who can execute the flaw to modify credentials and bypass authentication, given the local nature of the weakness described.
OpenCVE Enrichment