5.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Description
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.
Basic Information
ID
CVE-2025-9997
Source
schneider
Published
Sep 9, 2025 at 21:12
Affected Product
Vendor
Schneider Electric
Product
Saitel DR RTU
Version
all versions
Affected Versions
Schneider Electric Saitel DR RTU all versions
Schneider Electric Saitel DP RTU all versions
Schneider Electric Saitel DP RTU all versions