Schneider Electric Vulnerabilities and Affected Products
Vulnerabilities associated with Modicon Controllers M241/M251.
Products
Clear product- StruxureWare Data Center Expert15 vulnerabilities
- EcoStruxure Control Expert12 vulnerabilities
- Modicon M340 CPU (part numbers BMXP34*)12 vulnerabilities
- IGSS Data Server (IGSSdataServer.exe)10 vulnerabilities
- PowerChute™ Serial Shutdown10 vulnerabilities
- EcoStruxure Process Expert9 vulnerabilities
- IGSS Dashboard (DashBoard.exe)9 vulnerabilities
- Custom Reports (RMS16.dll)8 vulnerabilities
- IGSS Data Server(IGSSdataServer.exe)8 vulnerabilities
- EcoStruxure™ IT Data Center Expert7 vulnerabilities
- Modicon Controllers M241/M2517 vulnerabilities
- Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)7 vulnerabilities
- Modicon Momentum Unity M1E Processor (171CBU*)7 vulnerabilities
- OPC UA Modicon Communication Module7 vulnerabilities
- Pro-face BLUE7 vulnerabilities
- X80 advanced RTU Communication Module7 vulnerabilities
- Data Center Expert6 vulnerabilities
- EcoStruxure Operator Terminal Expert6 vulnerabilities
- EcoStruxure™ Power Monitoring Expert (PME)6 vulnerabilities
- EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Module6 vulnerabilities
- Modicon M580 CPU (part numbers BMEP* and BMEH*)6 vulnerabilities
- Sage 14106 vulnerabilities
- Sage 14306 vulnerabilities
- Sage 14506 vulnerabilities
- Sage 24006 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-13902MEDIUM | Generated title:Schneider Electric Modicon Controllers M241/M251/M258/LMC058 Stored Cross-Site ScriptingCWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload. CWE-79Mar 10, 2026 | CVSS5.1v4.0 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3117MEDIUM | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting configuration file paths that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser. CWE-79Jun 10, 2025 | CVSS5.1v4.0 | EPSS0.191% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3116HIGH | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted body data to the controller. CWE-20Jun 10, 2025 | CVSS7.1v4.0 | EPSS0.385% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3905MEDIUM | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting PLC system variables that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser. CWE-79Jun 10, 2025 | CVSS5.1v4.0 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3112HIGH | CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated malicious user sends manipulated HTTPS Content-Length header to the webserver. CWE-400Jun 10, 2025 | CVSS7.1v4.0 | EPSS0.526% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3899MEDIUM | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Certificates page on Webserver that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser. CWE-79Jun 10, 2025 | CVSS5.1v4.0 | EPSS0.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3898HIGH | CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to the webserver. CWE-20Jun 10, 2025 | CVSS7.1v4.0 | EPSS0.442% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |