<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:06:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-13905</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-13905</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Schneider Electric EcoStruxure™ Process Expert, Schneider Electric EcoStruxure™ Process Expert for AVEVA System Platform&lt;/p&gt;
&lt;p&gt;CWE-276: Incorrect Default Permissions vulnerability exists that could cause  privilege escalation through the reverse shell when  one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Schneider Electric EcoStruxure™ Process Expert, Schneider Electric EcoStruxure™ Process Expert for AVEVA System Platform&lt;/p&gt;
&lt;p&gt;CWE-276: Incorrect Default Permissions vulnerability exists that could cause  privilege escalation through the reverse shell when  one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-13905</guid>
    </item>
    <item>
      <title>SEVD-2026-013-02 — Incorrect Default Permissions Vulnerability on EcoStruxure™ Process Expert</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-013-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its EcoStruxureTM Process and EcoStruxure™ Process Expert &#13;
for AVEVA System Platform products. &#13;
The EcoStruxureTM Process is a single automation system to engineer, operate, and maintain your entire &#13;
infrastructure for a sustainable, productive and market-agile plant.&#13;
The EcoStruxure™ Process Expert for AVEVA System Platform product enables users to achieve operational &#13;
profitability from design engineering to meeting the demands of modern-day production. It provides an asset &#13;
centric and object-oriented automation platform to deploy system-wide standards in a digital ecosystem.&#13;
Failure to apply the Fix/Mitigations provided below may risk modification of the executable binaries, which &#13;
could result in privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its EcoStruxureTM Process and EcoStruxure™ Process Expert &#13;
for AVEVA System Platform products. &#13;
The EcoStruxureTM Process is a single automation system to engineer, operate, and maintain your entire &#13;
infrastructure for a sustainable, productive and market-agile plant.&#13;
The EcoStruxure™ Process Expert for AVEVA System Platform product enables users to achieve operational &#13;
profitability from design engineering to meeting the demands of modern-day production. It provides an asset &#13;
centric and object-oriented automation platform to deploy system-wide standards in a digital ecosystem.&#13;
Failure to apply the Fix/Mitigations provided below may risk modification of the executable binaries, which &#13;
could result in privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-013-02</guid>
    </item>
  </channel>
</rss>
