CVE-2025-54923 Details
Description
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
A deserialization vulnerability allowing remote code execution has been identified in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) 2022, 2023, 2024, and 2024 R2 versions, as well as in the Power Operation (EPO) and Power SCADA Operation (PSO) products with the Advanced Reporting and Dashboards Module. This vulnerability arises when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization, potentially compromising system integrity.
Users can upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R2, which includes a fix for this vulnerability. For those using EcoStruxure Power Operation, the update must be applied separately from Power Monitoring Expert. Customers should also follow the cybersecurity hardening guidelines provided with the product, ensure PME is running in an isolated network, deploy and configure the Windows firewall to limit access to appropriate network segments, enforce complex password policies, review server access permissions, and conduct regular audits of Windows-authenticated users with access to PME.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-224-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-224-02.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric EcoStruxure Power Monitoring Expert | 2022 2023 2024 2024 R2 |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Power Operation | All versions |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Power SCADA Operation | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion