Externally Controlled Reference to a Resource in Another Sphere in Schneider Electric products - CVE-2025-2875
Published: May 27, 2025
Vulnerability identifier: #VU109832
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2875
CWE-ID: CWE-610
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to externally controlled reference to a resource in another sphere. A remote attacker can manipulate a controller's webserver URL and gain access to sensitive information on the system.
Affected software
Modicon M258
Modicon LMC058
Modicon M241
Modicon M251
Modicon LMC058
Modicon M241
Modicon M251
How to mitigate CVE-2025-2875
Install updates from vendor's website.
Modicon M241 - update to 5.3.12.48
Modicon M251 - update to 5.3.12.48
Modicon M251 - update to 5.3.12.48