Back to Database
Status published
Medium
CVE-2023-25620
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability...
Vulnerability Description
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25620
Credits & Attribution
No credits recorded in the NVD database.
More from Schneider Electric
View All →CVE-2025-9997
CWE-78: Improper Neutralization of Special Elements used in an OS...
Medium
5.8
CVE-2025-9996
CWE-78: Improper Neutralization of Special Elements used in an OS...
Medium
5.8
CVE-2025-8453
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege...
High
8.4
CVE-2025-7746
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site...
Medium
5.3
CVE-2025-6788
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists...
Medium
5.3
Affected Vendor
Schneider Electric
View all reports →Affected Software
Modicon M340 CPU (part numbers BMXP34*) , Modicon M580 CPU (part numbers BMEP* and BMEH*), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S), Modicon Momentum Unity M1E Processor (171CBU*), Modicon MC80 (BMKC80), Legacy Modicon Quantum (140CPU65*), Legacy Modicon Premium CPUs (TSXP57*)
Vulnerable Versions:
prior to SV3.51, prior to V4.10, All , All
Timeline
Official Publish:
April 19th, 2023
Last Modified:
February 5th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H