25% (57) 480 views 5 pages

SESU Security Notification CVE-2025-5296

AI-enhanced description

This document details a high-severity vulnerability (CVE-2025-5296) in the Schneider Electric Software Update (SESU) product, specifically a CWE-59 "Link Following" flaw that could allow a low-privileged attacker to write arbitrary data to protected locations. The notification provides remediation via SESU version 3.0.12 and lists affected products, including EcoStruxure, Harmony, and PowerLogic series, along with mitigations for customers who cannot immediately apply the patch.

Uploaded by Chloé62
Download
/ 5
Loading document…