CVE-2024-11737: Schneider Electric Modicon Controllers m241 / m251

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.

Affected products

Published 2024-12-11. Last modified 2026-06-17.