CVE-2025-1060 Details
Description
CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
A vulnerability allowing cleartext transmission of sensitive information has been identified in the ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight-Channel Remote Annunciator. This vulnerability could lead to data exposure if network traffic is intercepted by an attacker.
Users are advised to operate these remote annunciator devices in a protected environment, minimizing network exposure and ensuring they are not accessible from the public internet or untrusted networks. Default passwords should be changed to prevent unauthorized access to device settings and information. Network segmentation should be implemented, along with a firewall to block unauthorized access to the annunciator's HTTP port. For more details, refer to the 'Installation Manual' for the ASCO 5310 and ASCO 5350, available on the Schneider Electric website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 13, 2025CISA-ADP
Assessed Feb 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=sevd-2025-042-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-01.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric ASCO 5310 | All versions |
CPE
Remediation
| |
| Schneider Electric ASCO 5350 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | New CVE Received | [email protected] |
Volerion