EcoStruxure Process Expert Security Notification – CVE-2025-0327
This document details a high-severity local privilege escalation vulnerability (CVE-2025-0327) in EcoStruxure Process Expert and EcoStruxure Process Expert for AVEVA System Platform, which could lead to loss of confidentiality, integrity, and availability of the engineering workstation. It provides remediation steps, including a software fix for version 2023 (v4.8.0.5715), and mitigations such as restricting service control permissions and using application whitelisting.
Failed to load PDF
Download insteadYou might also like
PYROTRONICS PIU Building Automation System Interface Manual
4 pages
Satchwell KMC P+I+D Controller Data Sheet
4 pages
SpaceLogic SHD100 and SHD101 Duct Humidity and Temperature Sensor Specification Sheet
3 pages
Andover Continuum Infinet II i2887 Terminal Controller Manual
6 pages
Satchwell RB2 Relay Unit Installation and Specification Guide
2 pages
Modicon M580, M340, Quantum, Premium Controllers Security Notification
8 pages
TAC Xenta 102-EF VAV Zone Controller Manual
6 pages
SpaceLogic MG900-SR Actuator Specification Sheet
6 pages
Modicon M340 Security Notification (CVE-2022-0222)
5 pages
SpaceLogic Touchscreen Room Controller Cybersecurity Hardening Guide
4 pages