CVE-2025-13905: Schneider Electric Ecostruxure Process Expert
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.
Affected products
- Schneider Electric Ecostruxure Process Expert: before 2025 (fixed in 2025)
- Schneider Electric Ecostruxure Process Expert For Aveva System Platform: any version
Published 2026-01-29. Last modified 2026-06-17.