CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

schneider-electric

modicon_m241_firmware

5 known vulnerabilities · sorted by CVSS score

CVE-2020-7487
CRITICAL9.8

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.

schneider-electric / ecostruxure_machine_expert+6
Network
Published Apr 22, 2020
CVE-2019-6820
HIGH8.2

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2

schneider-electric / modicon_m100_firmware+11
Network
Published May 22, 2019
CVE-2021-22699
HIGH7.5

Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.

schneider-electric / modicon_m241_firmware+1
Network
Published May 26, 2021
CVE-2020-7488
HIGH7.5

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.

schneider-electric / ecostruxure_machine_expert+6
Network
Published Apr 22, 2020
CVE-2024-6528
MEDIUM5.4

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.

schneider-electric / modicon_m241_firmware+4
Network
Published Jul 11, 2024