CVE-2025-13901
6.9
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: cybersecurity@se.com (Secondary)
Description
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.4.13.12 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M241 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.4.13.12 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M251 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.4.10.12 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M262 | All versions |
References (1)
Source: cybersecurity@se.com
Vendor AdvisoryMitigationPatch
Timeline
No history available yet.