CVE-2025-13957: Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.
Affected products
- Schneider Electric Ecostruxure It Data Center Expert Formerly Known As Struxureware Data Center Expert: up to and including v9.0
Published 2026-03-10. Last modified 2026-06-17.