CVE-2025-8449: Schneider Eelctric Ecostruxure Building Operation Workstation

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.

Affected products

Published 2025-08-20. Last modified 2026-06-17.