CVE-2025-13957 PUBLISHED

Assigner: schneider
Reserved: 03.12.2025 Published: 10.03.2026 Updated: 10.03.2026

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.5

Product Status

Vendor Schneider Electric
Product EcoStruxure™ IT Data Center Expert
Versions Default: unaffected
  • Version v9.0 and prior is affected

References

Problem Types

  • CWE-798: Use of Hard-coded Credentials CWE