CVE-2025-3116
MEDIUMSchneider Electric Modicon M241/M251 <5.3.12.51 & M258/LMC058 Authenticated DoS via HTTPS
Title source: llmDescription
CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted body data to the controller.
References (1)
Core 1
Scores
CVSS v3
6.5
EPSS
0.0038
EPSS Percentile
29.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (2)
Schneider Electric/Modicon Controllers M241/M251
Versions prior to 5.3.12.51
Schneider Electric/Modicon Controllers M258 / LMC058
All Versions
Published
Jun 10, 2025
Tracked Since
Feb 18, 2026