CVE-2025-3898

MEDIUM

Schneider Electric Modicon M241/M251 <5.3.12.51 & M262 <5.3.9.18 Authenticated DoS via Invalid HTTPS Data

Title source: llm
STIX 2.1

Description

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to the webserver.

Scores

CVSS v3 6.5
EPSS 0.0043
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
Schneider Electric/Modicon Controllers M241/M251 Versions prior to 5.3.12.51
Schneider Electric/Modicon Controllers M262 Versions prior to 5.3.9.18
Published Jun 10, 2025
Tracked Since Feb 18, 2026