CVE-2025-8448 Details
Description
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.
A vulnerability allowing unauthorized access to sensitive credential data has been identified in Schneider Electric's EcoStruxure Building Operation Enterprise Server, Enterprise Central, and Workstation, all versions prior to 7.0.1. This vulnerability arises from the exposure of local SMB traffic, which an attacker could capture between a valid user and the vulnerable products within the Building Management System (BMS) network.
Users can upgrade to EcoStruxure Building Operation versions 7.0.2.348, 6.0.4.10001 (CP8), or 5.0.3.17009 (CP16). After upgrading, it is recommended to follow the EBO hardening guidelines. For assistance, contact Schneider Electric's Customer Care Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-224-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-224-04.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric EcoStruxure Building Operation Enterprise Server | < 7.0.1 (semver) |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Building Operation Enterprise Central | All versions |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Building Operation Workstation | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2025 | CVE Modified | [email protected] |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion