CVE-2025-2002 Details
Description
CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.
A vulnerability allowing the insertion of sensitive information into log files has been identified in Schneider Electric's EcoStruxure Panel Server, all models, through version 2.0. This vulnerability could lead to the unintentional disclosure of FTP server credentials. The issue arises when the FTP server is active, the device is in debug mode, and the debug files are exported from the device.
Users can upgrade to version 2.1 or later of EcoStruxure Panel Server, which includes a fix for this vulnerability. This version is available for download from the Schneider Electric website. After upgrading, customers should ensure that debug mode is turned off to prevent credential exposure.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 12, 2025CISA-ADP
Assessed Mar 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric EcoStruxure Panel Server | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 12, 2025 | New CVE Received | [email protected] |
Volerion