Medium severity5.3NVD Advisory· Published Mar 10, 2026· Updated Jun 23, 2026
CVE-2025-13901
CVE-2025-13901
Description
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.
Affected products
5- cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:*Range: <5.4.13.12
- cpe:2.3:o:schneider-electric:modicon_m251_firmware:*:*:*:*:*:*:*:*Range: <5.4.13.12
- cpe:2.3:o:schneider-electric:modicon_m262_firmware:*:*:*:*:*:*:*:*Range: <5.4.10.12
- Range: Versions prior to 5.4.10.12
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor AdvisoryMitigationPatch
News mentions
0No linked articles in our index yet.