CVE Tools

Ecostruxure™ It Data Center Expert

7 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Ecostruxure™ It Data Center Expert, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

Ecostruxure™ It Data Center Expert CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ecostruxure™ It Data Center Expert CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-076
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical571%
  • High114%
  • Medium114%

Latest CVEs

The 7 most recently published vulnerabilities affecting Ecostruxure™ It Data Center Expert.

  1. CVE-2026-8045CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert us...6.5
  2. CVE-2025-50124A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation o...10.0
  3. CVE-2025-50125A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URL...10.0
  4. CVE-2025-50123A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a console...10.0
  5. CVE-2025-50122A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade ar...8.3
  6. CVE-2025-50121A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious fo...10.0
  7. CVE-2025-6438A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unautho...10.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store