CISA Warns of Critical Denial-of-Service Vulnerability in Schneider Electric Modicon Controllers
CISA has issued a critical alert for CVE-2025-6625, a vulnerability in Schneider Electric Modicon M340 controllers and communication modules that could lead to a denial-of-service attack.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a critical alert regarding a vulnerability affecting Schneider Electric's Modicon M340 Programmable Automation Controllers (PACs) and associated communication modules. Identified as CVE-2025-6625, the flaw is classified as an Improper Input Validation vulnerability, carrying a CVSS v3.1 base score of 7.5 (High).
Successful exploitation of this vulnerability can result in a Denial of Service (DoS) condition. Threat actors can trigger this by sending specifically crafted FTP commands to the affected devices. A successful attack would render the controllers and communication modules unavailable, potentially disrupting critical industrial operations.
The vulnerability impacts a range of Schneider Electric products, including various Ethernet and communication modules within the Modicon M340 and M580 product lines. Specific affected versions are detailed in the advisory, with some products, like the M580 Global Data module and Ethernet/Serial RTU Module, being affected across all versions. Other modules, such as certain Modbus/TCP Ethernet Modicon M340 modules, are vulnerable in versions prior to specific firmware releases (e.g., 3.60 and 6.80).
Schneider Electric has acknowledged the vulnerability and has released firmware updates to address it. Versions 3.60 of BMXNOE0100, 6.80 of BMXNOE0110, SV3.70 of Modicon M340 controllers, and SV1.7 IR27 of BMXNOR0200H are noted as containing fixes. Users are advised to apply these updates and reboot their devices to complete the firmware upgrade process.
For organizations unable or unwilling to immediately apply the patches, CISA and Schneider Electric recommend several mitigations. The primary recommendation is to ensure the FTP service is disabled when not in use, as it is disabled by default. Additionally, implementing network segmentation and firewalls to block unauthorized access to port 21 (FTP) is crucial. For remote access requirements, the use of VPN tunnels is advised.
The affected products are deployed globally across critical infrastructure sectors, including Chemical, Commercial Facilities, Critical Manufacturing, Energy, and Water and Wastewater. The widespread use of these industrial control systems underscores the potential impact of a successful DoS attack, which could lead to significant operational downtime and service disruptions.
This advisory highlights the ongoing security challenges within the Industrial Control Systems (ICS) landscape. Vulnerabilities in widely deployed operational technology (OT) equipment can have severe consequences, emphasizing the need for regular patching, robust network security, and diligent monitoring of vendor advisories.