CVE-2023-25620: Schneider Electric 140cpu65 Firmware
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
Affected products
- Schneider Electric 140cpu65 Firmware: any version
- Schneider Electric BMEH58S Firmware: any version
- Schneider Electric BMEP58S Firmware: any version
- Schneider Electric Modicon m340 Firmware: before 3.51 (fixed in 3.51)
- Schneider Electric Modicon m580 Firmware: before 4.10 (fixed in 4.10)
- Schneider Electric Modicon MC80 Firmware: any version
- Schneider Electric Modicon Momentum Unity m1e Processor Firmware: any version
- Schneider Electric TSXP57 Firmware: any version
Published 2023-04-19. Last modified 2026-06-17.