Denial of Service Vulnerability in Schneider Electric Web Server Products
CVE-2025-3112
7.1HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-3112?
An uncontrolled resource consumption vulnerability has been identified in Schneider Electric's web server products. This flaw could allow an authenticated user to manipulate the HTTPS Content-Length header, leading to potential Denial of Service attacks. By exploiting this vulnerability, malicious actors might disrupt service availability, impacting user access and operational efficiency.
Affected Version(s)
Modicon Controllers M241/M251 Versions prior to 5.3.12.51