CVE-2025-8448: Schneider Eelctric Ecostruxure Building Operation Enterprise Server
Low severity, CVSS 1.0. EPSS: 0.2% chance of exploitation in the next 30 days.
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.
Affected products
- Schneider Eelctric Ecostruxure Building Operation Enterprise Server
- Schneider Eelctric Ecostruxure Building Operation Workstation
- Schneider Electric Ecostruxure Enterprise Server
Published 2025-08-20. Last modified 2026-06-17.