Denial of Service Vulnerability in UPS Products by Unauthenticated Remote Attackers
CVE-2025-41703

7.5HIGH

What is CVE-2025-41703?

A vulnerability exists in various Uninterruptible Power Supply (UPS) products that allows unauthenticated remote attackers to conduct Denial of Service attacks by disabling output through the Modbus command interface. This flaw enables potential disruption of power supply services, showcasing the critical need for robust security measures in industrial control systems.

Affected Version(s)

QUINT4-UPS/24DC/24DC/10/EIP VC:00

QUINT4-UPS/24DC/24DC/20/EIP VC:00

QUINT4-UPS/24DC/24DC/40/EIP VC:00

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
.
CVE-2025-41703 : Denial of Service Vulnerability in UPS Products by Unauthenticated Remote Attackers