---
cve: "CVE-2025-13957"
severity: "HIGH"
cvss: 7.5
epss: "68%"
vendor: "Schneider Electric"
kev: false
exploited: false
published: "2026-03-10 18:17:52"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T21:20:40+02:00"
---

# CVE-2025-13957

> 7.5 HIGH

## Beschreibung

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Schwachstellen-Klasse

- **CWE-798** — Use of Hard-coded Credentials
  The product contains hard-coded credentials, such as a password or cryptographic key.

## Angriffsmuster (CAPEC)

- [CAPEC-70 — Try Common or Default Usernames and Passwords](https://capec.mitre.org/data/definitions/70.html) _(Severity: High)_
- [CAPEC-191 — Read Sensitive Constants Within an Executable](https://capec.mitre.org/data/definitions/191.html) _(Severity: Low)_

## ATT&CK-Techniken

- [T1078.001 — Valid Accounts:Default Accounts](https://attack.mitre.org/techniques/T1078/001/)
- [T1552.001 — Unsecured Credentials:Credentials in files](https://attack.mitre.org/techniques/T1552/001/)

## Referenzen

- <https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-05.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-13957) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
