Schneider Electric EcoStruxure IT Data Center Expert

MonitorCVSS 6.5ICS-CERT ICSA-26-181-03Jun 9, 2026
Schneider ElectricEnergy
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

EcoStruxure IT Data Center Expert versions 9.1.1 and earlier contain an XML-related vulnerability (CWE-611) that allows information disclosure. The product is a scalable monitoring software that collects and distributes critical device information across data center infrastructure. An authenticated user could exploit this to access sensitive information about monitored equipment and infrastructure. Vendor has released version 9.1.2 with a fix.

What this means
What could happen
An authenticated user with access to EcoStruxure IT Data Center Expert could read sensitive information about monitored equipment and infrastructure that should not be disclosed. This could expose details about data center layout, power systems, cooling infrastructure, and other critical equipment.
Who's at risk
Energy sector organizations and data center operators who rely on Schneider Electric EcoStruxure IT Data Center Expert for infrastructure monitoring. This affects any user with authentication access to the monitoring platform who could potentially access sensitive configuration and equipment details beyond their intended privileges.
How it could be exploited
An attacker with valid credentials to the EcoStruxure IT Data Center Expert monitoring interface could exploit an XML parsing flaw to access sensitive data not intended for their role or visibility level. The attacker must already have network access to the application and valid authentication credentials.
Prerequisites
  • Valid user credentials for EcoStruxure IT Data Center Expert
  • Network access to the EcoStruxure IT Data Center Expert application interface
  • Running version 9.1.1 or earlier
Requires valid authenticationInformation disclosure riskAffects critical infrastructure monitoring visibility
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
EcoStruxure IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)≤ 9.1.19.1.2
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate EcoStruxure IT Data Center Expert to version 9.1.2 or later
API: /api/v1/advisories/9ed66b93-d185-4b30-bf89-79ba9f0f7fd8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.