Cyber Posture

CVE-2025-1058

High

Published: 13 February 2025

Published
13 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score 0.0012 30.4th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.

Security Summary

CVE-2025-1058 is a CWE-494: Download of Code Without Integrity Check vulnerability in a Schneider Electric device. The issue arises when firmware is downloaded without proper integrity verification, potentially allowing malicious firmware to be installed. Published on 2025-02-13, it carries a CVSS v3.1 base score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), reflecting high severity primarily from impacts to integrity and availability.

An attacker requires only low privileges (PR:L) to exploit this vulnerability over the network (AV:N) with low attack complexity and no user interaction. Successful exploitation enables the download of malicious firmware, which can render the affected device inoperable, achieving high integrity (I:H) and availability (A:H) impacts with no confidentiality effects.

Schneider Electric has published Security and Safety Notice SEVD-2025-042-01, available at https://download.schneider-electric.com/files?p_Doc_Ref=sevd-2025-042-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-01.pdf, which provides further details on mitigation and remediation.

Details

CWE(s)
CWE-494

References