Vulnerability Description
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M241 Firmware | < 5.4.13.12 |
| Schneider-Electric | Modicon M241 | - |
| Schneider-Electric | Modicon M251 Firmware | < 5.4.13.12 |
| Schneider-Electric | Modicon M251 | - |
| Schneider-Electric | Modicon M262 Firmware | < 5.4.10.12 |
| Schneider-Electric | Modicon M262 | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-01&p_enDocVendor AdvisoryMitigationPatch
FAQ
What is CVE-2025-13901?
CVE-2025-13901 is a vulnerability with a CVSS score of 5.3 (MEDIUM). CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occ...
How severe is CVE-2025-13901?
CVE-2025-13901 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13901?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M241 Firmware, Schneider-Electric Modicon M241, Schneider-Electric Modicon M251 Firmware, Schneider-Electric Modicon M251, Schneider-Electric Modicon M262 Firmware.