Home
HIGH: 8.9 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:HDefault status
unaffected
8.3 (custom)
affected
Description
A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
Problem types
Product status
8.3 (custom)
References
seclists.org/fulldisclosure/2025/Jul/7
download.schneider-electric.com/...Name=SEVD-2025-189-01.pdf