CVE-2025-13901
published 2026-03-10CVE-2025-13901: CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.46%
36.5th percentile
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | modicon_m241_firmware | < 5.4.13.12 | 5.4.13.12 |
| schneider-electric | modicon_m251_firmware | < 5.4.13.12 | 5.4.13.12 |
| schneider-electric | modicon_m262_firmware | < 5.4.10.12 | 5.4.10.12 |
| schneider_electric | modicon_m241_m251 | — | — |
| schneider_electric | modicon_m262 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Modicon M241, M251, and M262
cisa_ics·2026-03-19·CVSS 6.9
[MEDIUM] Schneider Electric Modicon M241, M251, and M262
ICS Advisory
##
Schneider Electric Modicon M241, M251, and M262
Release DateMarch 19, 2026
Alert CodeICSA-26-078-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the product.
The following versions of Schneider Electric Modicon M241, M251, and M262 are affected:
- Modicon M241 versions prior to 5.4.13.12 Modicon_Controller_M241
- Modicon M251 versions prior to 5.4.13.12 Modicon_Controller_M251
- Modicon M262 versions prior to 5.4.10.12 Modicon_Controller_M262
CVSS
Vendor
Equipment
Vulnerabilities
| v3 5.3
| Schneider Electric
| Schneider Electric Modicon M241, M251, and M262
| Improp
GHSA
GHSA-qc8m-h3rg-94h4: CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unaut
ghsa_unreviewed·2026-03-10
CVE-2025-13901 [MEDIUM] CWE-404 GHSA-qc8m-h3rg-94h4: CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unaut
CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-10
Published