CVE-2025-54923
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-20

Last updated on: 2025-08-20

Assigner: Schneider Electric SE

Description
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-20
Last Modified
2025-08-20
Generated
2026-05-07
AI Q&A
2025-08-20
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
schneider_electric ecostruxure_power_monitoring_expert 2024
schneider_electric ecostruxure_power_scada_operation *
schneider_electric ecostruxure_power_operation *
schneider_electric ecostruxure_power_monitoring_expert 2024_r2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a CWE-502: Deserialization of Untrusted Data issue. It occurs when authenticated users send specially crafted data to a network-exposed service that performs unsafe deserialization. This can lead to remote code execution and compromise the integrity of the affected system.


How can this vulnerability impact me? :

The vulnerability can allow an attacker with authentication to execute arbitrary code remotely on the affected system, potentially leading to a full compromise of system integrity and unauthorized control over the system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart