CVE-2025-54927: Schneider Electric Ecostruxure Power Monitoring Expert Pme
Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.
Affected products
- Schneider Electric Ecostruxure Power Monitoring Expert Pme: version 2022 only; version 2023 only; version 2024 only; version 2024 R2 only
- Schneider Electric Ecostruxure Power Operation Epo Advanced Reporting And Dashboards Module
Published 2025-08-20. Last modified 2026-06-17.