<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:06:37 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-54924</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-54924</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Schneider Electric EcoStruxure™ Power Monitoring Expert (PME), Schneider Electric EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Module&lt;/p&gt;
&lt;p&gt;CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a specially crafted document to a vulnerable endpoint.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Schneider Electric EcoStruxure™ Power Monitoring Expert (PME), Schneider Electric EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Module&lt;/p&gt;
&lt;p&gt;CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a specially crafted document to a vulnerable endpoint.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-54924</guid>
    </item>
    <item>
      <title>ICSA-25-224-03 — Schneider Electric EcoStruxure Power Monitoring Expert</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-224-03</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Power Monitoring Expert (PME) and EcoStruxure Power Operation (EPO) and EcoStruxure Power SCADA Operation (PSO) products. EcoStruxure Power Monitoring Expert (PME) is an on-premises software used to help power critical and energy-intensive facilities maximize uptime and operational efficiency. Note: There are some instances of PME being deployed in a Managed Service model. EcoStruxure Power Operation (EPO) and EcoStruxure Power SCADA Operation (PSO) are on-premises software offers that provides a single platform to monitor and control medium and lower power systems. Failure to apply the remediation and/or mitigations provided below may risk deserialization of untrusted data, server-side request forgery and/or path traversal that could result in remote code execution, and/or unauthorized access to sensitive data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Power Monitoring Expert (PME) and EcoStruxure Power Operation (EPO) and EcoStruxure Power SCADA Operation (PSO) products. EcoStruxure Power Monitoring Expert (PME) is an on-premises software used to help power critical and energy-intensive facilities maximize uptime and operational efficiency. Note: There are some instances of PME being deployed in a Managed Service model. EcoStruxure Power Operation (EPO) and EcoStruxure Power SCADA Operation (PSO) are on-premises software offers that provides a single platform to monitor and control medium and lower power systems. Failure to apply the remediation and/or mitigations provided below may risk deserialization of untrusted data, server-side request forgery and/or path traversal that could result in remote code execution, and/or unauthorized access to sensitive data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-224-03</guid>
    </item>
  </channel>
</rss>
