Denial of Service Vulnerability in Schneider Electric Web Server Products
CVE-2025-3112

7.1HIGH

What is CVE-2025-3112?

An uncontrolled resource consumption vulnerability has been identified in Schneider Electric's web server products. This flaw could allow an authenticated user to manipulate the HTTPS Content-Length header, leading to potential Denial of Service attacks. By exploiting this vulnerability, malicious actors might disrupt service availability, impacting user access and operational efficiency.

Affected Version(s)

Modicon Controllers M241/M251 Versions prior to 5.3.12.51

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3112 : Denial of Service Vulnerability in Schneider Electric Web Server Products