# CVE-2025-50122

## Summary

- **CVE ID:** CVE-2025-50122
- **Severity:** HIGH
- **CVSS Score:** 8.9 (CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H)
- **CWE:** CWE-331
- **Published:** Jul 11, 2025
- **Last Modified:** Mar 12, 2026

## Description

A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the
password generation algorithm is reverse engineered with access to installation or upgrade artifacts.

## Affected Products

- Schneider Electric — EcoStruxure™ IT Data Center Expert (8.3)

## References

- [CNA](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-189-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-189-01.pdf)
- [CVE](http://seclists.org/fulldisclosure/2025/Jul/7)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._