Schneider Electric Modicon Controllers Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Schneider Electric's Modicon Controllers M241, M251, M258, LMC058, and M262, all versions prior to specific fixed releases. This vulnerability arises from improper input validation, allowing an authenticated malicious user to send specially crafted HTTPS requests with malformed body data to the controller. The exploitation of this vulnerability could lead to a loss of availability, causing the controller to become unresponsive or fail to perform its intended functions.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition, where the affected controller becomes unresponsive or fails to function properly, disrupting any processes or applications relying on it.

Remediation

Users of Modicon Controllers M241/M251 can upgrade to version 5.3.12.51, while those using Modicon Controllers M262 should upgrade to version 5.3.9.18. Both updates can be downloaded from the respective product pages on the Schneider Electric website. For Modicon M258/LMC058, a remediation plan is being established for future versions, and users should apply recommended cybersecurity best practices to reduce the risk of exploit.

Added: Jun 10, 2025, 10:17 AM
Updated: Jun 10, 2025, 10:17 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.9
remediation
7.9
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.