7.5
CVE-2025-41653
- EPSS 0.34%
- Veröffentlicht 27.05.2025 08:38:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
Weidmueller: Denial-of-Service Vulnerability in the web server functionality of Industrial Ethernet Switches
An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicious header, potentially causing the server to crash or become unresponsive.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWeidmueller
≫
Produkt
IE-SW-VL05M-5TX
Default Statusunaffected
Version
0.0.0
Version <
3.6.32
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-VL05MT-5TX
Default Statusunaffected
Version
0.0.0
Version <
3.6.32
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-VL08MT-8TX
Default Statusunaffected
Version
0.0.0
Version <
3.5.36
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-VL08MT-5TX-1SC-2SCS
Default Statusunaffected
Version
0.0.0
Version <
3.5.36
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-VL08MT-6TX-2SC
Default Statusunaffected
Version
0.0.0
Version <
3.5.36
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-VL08MT-6TX-2ST
Default Statusunaffected
Version
0.0.0
Version <
3.5.36
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-VL08MT-6TX-2SCS
Default Statusunaffected
Version
0.0.0
Version <
3.5.36
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-PL10M-3GT-7TX
Default Statusunaffected
Version
0.0.0
Version <
3.3.34
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-PL10MT-3GT-7TX
Default Statusunaffected
Version
0.0.0
Version <
3.3.34
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-PL16M-16TX
Default Statusunaffected
Version
0.0.0
Version <
3.4.32
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-PL16MT-16TX
Default Statusunaffected
Version
0.0.0
Version <
3.4.32
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-PL18M-2GC-16TX
Default Statusunaffected
Version
0.0.0
Version <
3.4.40
Status
affected
HerstellerWeidmueller
≫
Produkt
IE-SW-PL18MT-2GC-16TX
Default Statusunaffected
Version
0.0.0
Version <
3.4.40
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.566 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-410 Insufficient Resource Pool
The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.