Incorrect Calculation of Buffer Size in Schneider Electric products - CVE-2024-11425
Published: February 7, 2025
Vulnerability identifier: #VU103704
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11425
CWE-ID: CWE-131
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect calculation of buffer size. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.
Affected software
BMENOR2200H
EVLink Pro AC
Modicon M580 CPU Safety
Modicon M580
EVLink Pro AC
Modicon M580 CPU Safety
Modicon M580
How to mitigate CVE-2024-11425
Install updates from vendor's website.
EVLink Pro AC - update to 1.3.10
Modicon M580 CPU Safety - update to 4.21
Modicon M580 - update to 4.30
Modicon M580 CPU Safety - update to 4.21
Modicon M580 - update to 4.30