PatchSiren cyber security CVE debrief
CVE-2025-2222 Schneider Electric CVE debrief
CVE-2025-2222 is a CVSS 7.5 information-disclosure issue affecting Schneider Electric ConneXium Network Manager v2.0.01. The advisory describes a CWE-552 condition over HTTPS that could expose information and, in a man-in-the-middle scenario, create a path toward privilege escalation. Schneider Electric says the product is end-of-life, the webserver is disabled by default, and customers should apply the published mitigations and hardening guidance.
- Vendor
- Schneider Electric
- Product
- ConneXium Network Manager
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-08
- Original CVE updated
- 2025-04-08
- Advisory published
- 2025-04-08
- Advisory updated
- 2025-04-08
Who should care
Operators and administrators who still use Schneider Electric ConneXium Network Manager v2.0.01, especially in industrial or OT environments where the product may be reachable over HTTPS or exposed on enterprise networks. Network and security teams supporting deprecated OT software should also review the mitigation guidance.
Technical summary
The source advisory attributes the issue to CWE-552 (files or directories accessible to external parties). In the provided description, access over HTTPS could leak information, and a man-in-the-middle attack could contribute to potential privilege escalation. The affected product listed in the CSAF advisory is Schneider Electric ConneXium Network Manager v2.0.01. Schneider Electric notes that the webserver is disabled by default and recommends disabling it, along with workstation, network, and site-hardening measures. The product is also stated to be end-of-life.
Defensive priority
High for any environment that still has the affected product deployed, because the product is unsupported and the issue is network-reachable with high confidentiality impact. Priority is lower only if the product is not present or is fully isolated and the webserver is already disabled, but the end-of-life status still warrants replacement planning.
Recommended defensive actions
- Confirm whether Schneider Electric ConneXium Network Manager v2.0.01 is deployed anywhere in your environment.
- Disable the webserver if it is enabled; Schneider Electric states it is disabled by default.
- Apply Schneider Electric's recommended workstation, network, and site-hardening guidance from the published security notice.
- Treat the product as end-of-life and begin migration or replacement planning.
- Review exposure of any HTTPS service associated with the product and limit access to trusted management networks only.
- Monitor the CISA and Schneider Electric advisories for any updated guidance.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-107-03 and Schneider Electric's security notice SEVD-2025-098-01, both published on 2025-04-08. The source corpus identifies one affected product, Schneider Electric ConneXium Network Manager v2.0.01, and provides the mitigation guidance noted above. No KEV listing was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-2222 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-2222
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-2222 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-2222
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-107-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/us/en/download/document/7EN52-0390
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.