PatchSiren cyber security CVE debrief
CVE-2025-0813 Schneider Electric CVE debrief
CVE-2025-0813 is a medium-severity authentication bypass affecting Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) versions 2.1 through 2.9. The issue is specifically tied to an attacker who has physical access to the EPAS-UI computer and can reboot the workstation and interrupt the normal boot process. Schneider Electric states that version 2.10 includes a fix, and CISA published the advisory on 2025-03-18.
- Vendor
- Schneider Electric
- Product
- EcoStruxure Power Automation System User Interface (EPAS-UI)
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-18
- Original CVE updated
- 2025-03-18
- Advisory published
- 2025-03-18
- Advisory updated
- 2025-03-18
Who should care
Industrial control system operators, plant engineers, OT administrators, and site security teams responsible for EPAS-UI deployments, especially where workstations are physically accessible or shared among multiple personnel.
Technical summary
The advisory describes an authentication bypass in EPAS-UI that can occur when an unauthorized user with no permission rights has physical access to the workstation, reboots it, and interrupts the normal boot process. The affected product range is EPAS-UI >= 2.1 and <= 2.9. The advisory lists CVSS v3.1 vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H with a score of 6.8, reflecting that the attack requires physical proximity but can have high impact if successful.
Defensive priority
Medium, with higher urgency for environments where EPAS-UI workstations are not strictly controlled physically or where local access cannot be reliably prevented.
Recommended defensive actions
- Upgrade EcoStruxure Power Automation System User Interface (EPAS-UI) to version 2.10, which Schneider Electric identifies as the fixed release.
- If immediate upgrading is not possible, apply the vendor mitigation to rename C:\MCIS\Bin\MCIS.chm to MCIS.old and restart the machine, following the advisory instructions exactly.
- Restrict physical access to EPAS-UI workstations and prevent unauthorized users from reaching the console or reboot controls.
- Apply ICS segmentation and minimize network exposure for control-system devices, consistent with the CISA and Schneider Electric guidance referenced in the advisory.
- Use locked cabinets and other physical controls for controllers and related OT assets where applicable.
- Review local administrative access and workstation boot protections as part of site hardening, since the attack path depends on interrupting the normal boot process.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-077-01 for Schneider Electric EPAS-UI, published 2025-03-18 and unchanged in the supplied metadata. The source data identifies affected versions as EPAS-UI 2.1 through 2.9 and provides the vendor remediation to install version 2.10. The CVSS v3.1 vector in the supplied corpus is AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, supporting the physical-access dependency described in the advisory. No KEV entry is included in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0813 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0813
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0813 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0813
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-077-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-077-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.