Improper Input Validation in Schneider Electric Network Devices
CVE-2025-0814
6.9MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 13 February 2025
What is CVE-2025-0814?
An improper input validation vulnerability exists in certain Schneider Electric network devices, allowing attackers to send malicious IEC61850-MMS packets. When exploited, this vulnerability could lead to a Denial-of-Service condition, disrupting network services on affected devices. It is important to note that while the network services may be impacted, the core functionality of the device remains operational during such attacks, posing a risk of service disruption without complete device failure.
Affected Version(s)
Enerlin’X eIFE (LV851001) All versions
Enerlin’X IFE interface (LV434001) All versions