PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-0813 Schneider Electric CVE debrief

CVE-2025-0813 is a medium-severity authentication bypass affecting Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) versions 2.1 through 2.9. The issue is specifically tied to an attacker who has physical access to the EPAS-UI computer and can reboot the workstation and interrupt the normal boot process. Schneider Electric states that version 2.10 includes a fix, and CISA published the advisory on 2025-03-18.

Vendor
Schneider Electric
Product
EcoStruxure Power Automation System User Interface (EPAS-UI)
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-18
Original CVE updated
2025-03-18
Advisory published
2025-03-18
Advisory updated
2025-03-18

Who should care

Industrial control system operators, plant engineers, OT administrators, and site security teams responsible for EPAS-UI deployments, especially where workstations are physically accessible or shared among multiple personnel.

Technical summary

The advisory describes an authentication bypass in EPAS-UI that can occur when an unauthorized user with no permission rights has physical access to the workstation, reboots it, and interrupts the normal boot process. The affected product range is EPAS-UI >= 2.1 and <= 2.9. The advisory lists CVSS v3.1 vector AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H with a score of 6.8, reflecting that the attack requires physical proximity but can have high impact if successful.

Defensive priority

Medium, with higher urgency for environments where EPAS-UI workstations are not strictly controlled physically or where local access cannot be reliably prevented.

Recommended defensive actions

  • Upgrade EcoStruxure Power Automation System User Interface (EPAS-UI) to version 2.10, which Schneider Electric identifies as the fixed release.
  • If immediate upgrading is not possible, apply the vendor mitigation to rename C:\MCIS\Bin\MCIS.chm to MCIS.old and restart the machine, following the advisory instructions exactly.
  • Restrict physical access to EPAS-UI workstations and prevent unauthorized users from reaching the console or reboot controls.
  • Apply ICS segmentation and minimize network exposure for control-system devices, consistent with the CISA and Schneider Electric guidance referenced in the advisory.
  • Use locked cabinets and other physical controls for controllers and related OT assets where applicable.
  • Review local administrative access and workstation boot protections as part of site hardening, since the attack path depends on interrupting the normal boot process.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-25-077-01 for Schneider Electric EPAS-UI, published 2025-03-18 and unchanged in the supplied metadata. The source data identifies affected versions as EPAS-UI 2.1 through 2.9 and provides the vendor remediation to install version 2.10. The CVSS v3.1 vector in the supplied corpus is AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, supporting the physical-access dependency described in the advisory. No KEV entry is included in the provided corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-0813 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-0813

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-0813 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0813

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-077-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-077-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.