CVE-2025-3116

MEDIUM

Schneider Electric Modicon M241/M251 <5.3.12.51 & M258/LMC058 Authenticated DoS via HTTPS

Title source: llm
STIX 2.1

Description

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted body data to the controller.

Scores

CVSS v3 6.5
EPSS 0.0038
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
Schneider Electric/Modicon Controllers M241/M251 Versions prior to 5.3.12.51
Schneider Electric/Modicon Controllers M258 / LMC058 All Versions
Published Jun 10, 2025
Tracked Since Feb 18, 2026