77% (10) 304 views 5 pages

Modicon M241, M251, M258, LMC058 Security Notification (CVE-2025-2875)

AI-enhanced description

This document details a high-severity vulnerability (CVE-2025-2875) in Schneider Electric Modicon M241, M251, M258, and LMC058 programmable logic controllers, which could allow an unauthenticated attacker to read arbitrary files via webserver URL manipulation. It provides remediation steps, including firmware updates to versions v5.3.12.48 (M241/M251) and v5.0.4.19 (M258/LMC058), as well as mitigations such as network segmentation and webserver deactivation.

Uploaded by santiago.gonzalez
Download
/ 5
Loading document…