Home

Description

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.

PUBLISHED Reserved 2025-06-27 | Published 2025-07-11 | Updated 2025-07-22 | Assigner schneider




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-668 Exposure of Resource to Wrong Sphere

Product status

Default status
unaffected

2023 (custom) before All
affected

2023 R2 (custom) before All
affected

2024 (custom) before All
affected

2024 R2 (custom) before All
affected

Default status
unaffected

2022 w/ Advanced Reporting Module (custom) before All
affected

2024 w/ Advanced Reporting Module (custom) before All
affected

References

download.schneider-electric.com/...Name=SEVD-2025-189-04.pdf

cve.org (CVE-2025-6788)

nvd.nist.gov (CVE-2025-6788)

Download JSON