Description
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
Scores
CVSS v3
7.5
EPSS
0.0034
EPSS Percentile
56.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-131
Status
published
Products (4)
Schneider Electric/BMENOR2200H
All Versions
Schneider Electric/EVLink Pro AC
Versions prior to v1.3.10
Schneider Electric/Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)
Versions prior to SV4.30
Schneider Electric/Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)
Versions prior to SV4.21
Published
Jan 17, 2025
Tracked Since
Feb 18, 2026