Junglewise Threat Intelligence

CVE-2025-13901: Schneider Electric Modicon DoS in Machine Expert protocol

CVE-2025-13901 · Severity: medium · CVSS 5.3 · Published 2026-03-10

Vendors: Schneider Electric.

Executive brief

Schneider Electric Modicon controllers, which are used to automate industrial machinery and processes, are vulnerable to a denial-of-service attack. An unauthenticated attacker can send specially crafted network traffic to the device to exhaust its communication channels. This can prevent legitimate users or systems from communicating with the controller, potentially disrupting industrial operations.

Technical details

A CWE-404 (Improper Resource Shutdown or Release) vulnerability exists in the Machine Expert protocol implementation of several Schneider Electric Modicon controllers. An unauthenticated remote attacker can exploit this by sending malicious payloads designed to occupy and exhaust active communication channels. This results in a partial Denial of Service (DoS) condition where legitimate communication is blocked. The vulnerability affects Modicon M241/M251 firmware versions prior to 5.4.13.12 and Modicon M262 firmware versions prior to 5.4.10.12. Patches have been released to address this issue.

Affected products

  • Schneider Electric Modicon M241/M251 Firmware Prior to 5.4.13.12
  • Schneider Electric Modicon M262 Firmware Prior to 5.4.10.12

Timeline

  • 2026-03-10: advisory: Initial advisory published by Schneider Electric
  • 2026-03-10: disclosed

References

Related threats