Denial of Service Vulnerability in Modbus Service by Unauthenticated Remote Attacker
CVE-2025-41704

5.3MEDIUM

What is CVE-2025-41704?

An unauthenticated remote attacker could exploit a vulnerability in the Modbus service by sending specific function and sub-function codes. This exploit can lead to a denial of service, disrupting the availability of the Modbus service while safeguarding core functionalities. Organizations using affected versions of the Modbus service should take preventive measures to mitigate the risk.

Affected Version(s)

QUINT4-UPS/24DC/24DC/10/EIP VC:00

QUINT4-UPS/24DC/24DC/20/EIP VC:00

QUINT4-UPS/24DC/24DC/40/EIP VC:00

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
.
CVE-2025-41704 : Denial of Service Vulnerability in Modbus Service by Unauthenticated Remote Attacker