Schneider Electric Modicon Controllers Confidentiality Vulnerability via Externally Controlled Resource References

Vulnerability

A vulnerability allowing an unauthenticated attacker to manipulate the web server URL of affected Schneider Electric Modicon controllers, specifically the M241, M251, M258, and LMC058 models, could lead to unauthorized access to confidential resources. This vulnerability arises from externally controlled references to resources in another sphere, potentially allowing for an unauthenticated read of arbitrary files and a loss of confidential data stored on the controller.

Impact

Exploitation of this vulnerability could result in an unauthorized read of arbitrary files, leading to a loss of confidential data stored on the affected controller.

Remediation

Users of Modicon Controllers M241/M251 should update to version 5.3.12.48. For Modicon Controllers M258 and LMC058, Schneider Electric is developing a remediation plan for future versions that will address this vulnerability. Until then, users should apply recommended mitigations, such as using the controllers in a protected environment, managing user rights and passwords, deactivating the web server when not needed, using encrypted communication links, segmenting networks, and blocking unauthorized access to HTTP and HTTPS ports.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.