The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Building Operation Enterprise Server All 7.x versions prior to 7.0.2.348
- Schneider Electric EcoStruxure™ Building Operation Enterprise Server All 6.x versions prior to 6.0.4.10001 (CP8)
- Schneider Electric EcoStruxure™ Building Operation Enterprise Server All 5.x versions prior to 5.0.3.17009 (CP16)
- Schneider Electric EcoStruxure™ Building Operation Enterprise Central All 7.x versions prior to 7.0.2.348
- Schneider Electric EcoStruxure™ Building Operation Enterprise Central All 6.x versions prior to 6.0.4.10001 (CP8)
- Schneider Electric EcoStruxure™ Building Operation Enterprise Central All 5.x versions prior to 5.0.3.17009 (CP16)
- Schneider Electric EcoStruxure™ Building Operation Workstation All 7.x versions prior to 7.0.2.348
- Schneider Electric EcoStruxure™ Building Operation Workstation All 6.x versions prior to 6.0.4.10001 (CP8)
- Schneider Electric EcoStruxure™ Building Operation Workstation All 5.x versions prior to 5.0.3.17009 (CP16)
- Summary
- CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.
- Remediation
- The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these vulnerabilities: • 7.0.2.348 Step1: Locate the appropriate version for your system on the [EcoExpert Software Center](https://ecoxpert.se.com/software-center/building-automation/ebo-system/building-operation-2025-version-7.0). Step 2: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7).
