VYPR

SEVD-2025-189-01

by Schneider Electric

CVEs (2)

  • CVE-2025-50124HigJul 11, 2025
    risk 0.47cvss epss 0.00

    A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation of a setup script.

  • CVE-2025-50123HigJul 11, 2025
    risk 0.47cvss epss 0.00

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a console and through exploitation of the hostname input.