Improper Resource Shutdown in Machine Expert by Schneider Electric
CVE-2025-13901

6.9MEDIUM

What is CVE-2025-13901?

An improper resource shutdown vulnerability has been identified in Schneider Electric's Machine Expert. This flaw allows an unauthenticated attacker to exploit the system by sending specially crafted payloads, which can occupy active communication channels, potentially causing a partial Denial of Service. Addressing this issue is crucial to maintaining the stability and security of deployed environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Modicon M241/M251 Versions prior to 5.4.13.12

Modicon M262 Versions prior to 5.4.10.12

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.