VDB

SEVD-2025-189-03

SEVD-2025-189-03 PUBLISHED CVSS 8.100000381469727 HIGH

Schneider Electric is aware of multiple vulnerabilities disclosed in PostgreSQL. Many vendors, including Schneider Electric, use PostgreSQL in their offers. PostgreSQL is a database server that is used as a data store for multiple products. Schneider Electric installs a version of PostgreSQL with its EcoStruxure™ Power Operation https://www.se.com/us/en/product-range/65405-ecostruxure-power-operation/?parent-subcategory-id=59326966&filter=business-4-low-voltage-products-and-systems#overview software. EcoStruxure™ Power Operation (EPO) is an on-premises software offer that provides a single platform to monitor and control medium and lower power systems. Failure to apply the remediations and mitigations below could result in loss of system functionality or unauthorized access to system functions.

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
EcoStruxure™ Power Operation (EPO) 2022 CU6 and prior
EcoStruxure™ Power Operation 2024 CU2
EcoStruxure™ Power Operation (EPO) 2024 CU1 and prior
EcoStruxure™ Power Operation 2022 CU7

Timeline

  • Apr 28, 2025 PoC Published
  • Jul 8, 2025 CVE Published
  • Feb 10, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›