Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-0813

CVSS 6.8 · Medium EPSS 0.01% · P1
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-0813

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Schneider Electric EcoStruxure Power Automation System User Interface 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Schneider Electric EcoStruxure Power Automation System User Interface是法国施耐德电气(Schneider Electric)公司的一款施耐德电气用于电力自动化系统的用户界面软件。用于操作人员与电力自动化系统交互,提高操作效率。 Schneider Electric EcoStruxure Power Automation System User Interface v2.1版本至v2.9版本存在授权问题漏洞,该漏洞源于身份验证不当,可能
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Schneider ElectricEcoStruxure Power Automation System User Interface (EPAS-UI) - Secured Versions v2.1 up to and including v2.9 -

II. Public POCs for CVE-2025-0813

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-0813

登录查看更多情报信息。

Same Patch Batch · Schneider Electric · 2025-03-12 · 3 CVEs total

CVE-2025-19609.8 CRITICALSchneider Electric WebHMI 安全漏洞
CVE-2025-20026.0 MEDIUMSchneider Electric EcoStruxure Panel Server 日志信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-0813

No comments yet


Leave a comment