CVE-2024-11425: Schneider Electric BMENOR2200H
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
Affected products
- Schneider Electric BMENOR2200H: any version
- Schneider Electric Evlink Pro Ac: before v1.3.10 (fixed in v1.3.10)
- Schneider Electric Modicon m580 CPU Part Numbers Bmep* And Bmeh*, Excluding m580 CPU Safety
- Schneider Electric Modicon m580 CPU Safety Part Numbers BMEP58*S And BMEH58*S
Published 2025-01-17. Last modified 2026-06-17.