Denial of Service Vulnerability in UPS Products by Unauthenticated Remote Attackers
CVE-2025-41703
7.5HIGH
What is CVE-2025-41703?
A vulnerability exists in various Uninterruptible Power Supply (UPS) products that allows unauthenticated remote attackers to conduct Denial of Service attacks by disabling output through the Modbus command interface. This flaw enables potential disruption of power supply services, showcasing the critical need for robust security measures in industrial control systems.
Affected Version(s)
QUINT4-UPS/24DC/24DC/10/EIP VC:00
QUINT4-UPS/24DC/24DC/20/EIP VC:00
QUINT4-UPS/24DC/24DC/40/EIP VC:00
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research