Ecostruxure™ It Data Center Expert
7 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ecostruxure™ It Data Center Expert, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
Ecostruxure™ It Data Center Expert CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 6 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High1
- Medium1
Latest CVEs
The 7 most recently published vulnerabilities affecting Ecostruxure™ It Data Center Expert.
- CVE-2026-8045CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert us...6.5
- CVE-2025-50124A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation o...10.0
- CVE-2025-50125A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URL...10.0
- CVE-2025-50123A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a console...10.0
- CVE-2025-50122A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade ar...8.3
- CVE-2025-50121A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious fo...10.0
- CVE-2025-6438A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unautho...10.0
Product grouping is registry-driven, with AI assist and human review. How it works