Cyber Posture

CVE-2025-1059

High

Published: 13 February 2025

Published
13 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0067 71.4th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of the device.

Security Summary

CVE-2025-1059 is a CWE-770 vulnerability involving allocation of resources without limits or throttling in the webserver of Schneider Electric devices. Published on 2025-02-13, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The flaw enables communications to stop on the affected device when malicious packets are sent to its webserver.

A remote, unauthenticated attacker with network access to the device can exploit this vulnerability with low complexity and no user interaction required. Successful exploitation results in a denial-of-service condition, disrupting device communications without impacting confidentiality or integrity.

Mitigation details are provided in Schneider Electric's Security and Safety Notice SEVD-2025-042-01, accessible at https://download.schneider-electric.com/files?p_Doc_Ref=sevd-2025-042-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-01.pdf.

Details

CWE(s)
CWE-770

References