CVE-2025-1058
Published: 13 February 2025
Description
CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.
Security Summary
CVE-2025-1058 is a CWE-494: Download of Code Without Integrity Check vulnerability in a Schneider Electric device. The issue arises when firmware is downloaded without proper integrity verification, potentially allowing malicious firmware to be installed. Published on 2025-02-13, it carries a CVSS v3.1 base score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), reflecting high severity primarily from impacts to integrity and availability.
An attacker requires only low privileges (PR:L) to exploit this vulnerability over the network (AV:N) with low attack complexity and no user interaction. Successful exploitation enables the download of malicious firmware, which can render the affected device inoperable, achieving high integrity (I:H) and availability (A:H) impacts with no confidentiality effects.
Schneider Electric has published Security and Safety Notice SEVD-2025-042-01, available at https://download.schneider-electric.com/files?p_Doc_Ref=sevd-2025-042-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-01.pdf, which provides further details on mitigation and remediation.
Details
- CWE(s)