PatchSiren cyber security CVE debrief
CVE-2025-3112 Schneider Electric CVE debrief
CVE-2025-3112 is a CWE-400 uncontrolled resource consumption issue in Schneider Electric Modicon Controllers M241 and M251. According to the CISA CSAF advisory, an authenticated malicious user can send a manipulated HTTPS Content-Length header to the webserver and cause denial of service. The advisory lists affected versions prior to 5.3.12.51 and notes that remediation is available.
- Vendor
- Schneider Electric
- Product
- Modicon Controllers M241
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2025-07-08
- Advisory published
- 2025-06-10
- Advisory updated
- 2025-07-08
Who should care
Industrial control system operators, Schneider Electric Modicon M241/M251 administrators, and OT security teams responsible for devices where the controller webserver is enabled or reachable. Organizations using EcoStruxure Machine Expert or EcoStruxure Automation Expert - Motion for firmware updates should also review the remediation path.
Technical summary
CVE-2025-3112 affects Schneider Electric Modicon Controllers M241 and M251 versions prior to 5.3.12.51. The issue is classified as CWE-400 (Uncontrolled Resource Consumption). The supplied advisory says an authenticated attacker with low privileges can manipulate the HTTPS Content-Length header sent to the webserver and trigger a denial of service. CISA lists the CVSS v3.1 vector as AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (6.5 medium).
Defensive priority
Medium; prioritize remediation for any M241/M251 deployment where the webserver is enabled or exposed to broader network access.
Recommended defensive actions
- Update Modicon Controllers M241 to version 5.3.12.51 and reboot after applying the fix using EcoStruxure Automation Expert - Motion v24.1 or EcoStruxure Machine Expert v2.3 as directed by the vendor advisory.
- Update Modicon Controllers M251 to version 5.3.12.51 and reboot after applying the fix using EcoStruxure Automation Expert - Motion v24.1 or EcoStruxure Machine Expert v2.3 as directed by the vendor advisory.
- If you cannot remediate immediately, deactivate the webserver when it is not needed.
- Restrict access to the controllers by using protected environments, network segmentation, and firewall rules that block unauthorized access to ports 80/HTTP and 443/HTTPS.
- Use VPN tunnels for remote access, keep user management enabled, and use strong passwords.
- Use encrypted communication links and follow Schneider Electric's product-specific hardening guidance for Modicon and associated equipment.
Evidence notes
Primary evidence comes from CISA CSAF advisory ICSA-25-175-03 (published 2025-06-10, revised 2025-07-08). The advisory identifies Schneider Electric Modicon Controllers M241 and M251 as affected products, with versions prior to 5.3.12.51 impacted, and states that remediation is available in 5.3.12.51. The provided description and CVSS vector indicate a network-reachable denial-of-service condition requiring low-privilege authentication, caused by manipulated HTTPS Content-Length handling in the webserver. The revision history shows the July update added remediation availability via EcoStruxure Machine Expert v2.3 for updating M241/M251 firmware.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-3112 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-3112
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-3112 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3112
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-175-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/us/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.