Cross-site Scripting Vulnerability in Schneider Electric Products
CVE-2025-3117
5.1MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-3117?
This vulnerability arises from improper neutralization of user input during the generation of web pages, specifically impacting Schneider Electric's configuration file paths. An authenticated malicious user may exploit this weakness to inject unvalidated data, potentially allowing them to read or modify data in a victim's browser. Organizations using affected Schneider Electric products should apply recommended patches and review their security configurations to mitigate potential risks.
Affected Version(s)
Modicon Controllers M241/M251 Versions prior to 5.3.12.51
Modicon Controllers M262 Versions prior to 5.3.9.18