CVE-2025-1059
Published: 13 February 2025
Description
CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of the device.
Security Summary
CVE-2025-1059 is a CWE-770 vulnerability involving allocation of resources without limits or throttling in the webserver of Schneider Electric devices. Published on 2025-02-13, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The flaw enables communications to stop on the affected device when malicious packets are sent to its webserver.
A remote, unauthenticated attacker with network access to the device can exploit this vulnerability with low complexity and no user interaction required. Successful exploitation results in a denial-of-service condition, disrupting device communications without impacting confidentiality or integrity.
Mitigation details are provided in Schneider Electric's Security and Safety Notice SEVD-2025-042-01, accessible at https://download.schneider-electric.com/files?p_Doc_Ref=sevd-2025-042-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-01.pdf.
Details
- CWE(s)