Schneider Electric
Modicon Controllers M241 / M251
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2025-13902 | 10 Mar 2026 | Versions prior to 5.4.13.12; All versions | Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M241 to the latest Firmware and perform reboot. For instructions refer to Modicon M241 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003059/ | Update reference ↗ |
| CVE-2025-3117 | 10 Jun 2025 | Versions prior to 5.3.12.51; Versions prior to 5.3.9.18 | Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2025-3116 | 10 Jun 2025 | Versions prior to 5.3.12.51; All Versions | Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2025-3905 | 10 Jun 2025 | Versions prior to 5.3.12.51; All Versions | Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2025-3112 | 10 Jun 2025 | Versions prior to 5.3.12.51 | Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2025-3899 | 10 Jun 2025 | Versions prior to 5.3.12.51 | Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2025-3898 | 10 Jun 2025 | Versions prior to 5.3.12.51; Versions prior to 5.3.9.18 | Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2025-2875 | 14 May 2025 | Versions prior to v5.3.12.48; All versions | Versions 5.3.12.48 of Modicon Controllers M241 include a fix for this vulnerability and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware * Use the Controller Assistant feature of EcoStruxure™ Automation Expert - Motion V24.1 or EcoStruxure™ Machine Expert V2.3 to update the M241/M251 firmware and perform a reboot. * EcoStruxure™ Automation Expert - Motion V24.1 and EcoStruxure™ Machine Expert V2.3 are available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER * Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”. | Update reference ↗ |
| CVE-2024-11737 | 11 Dec 2024 | All versions | Modicon M241/M251 Firmware version 5.2.11.29 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application that is part of EcoStruxure™ Machine Expert: https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ By using Controller Assistant update Modicon Controller M241/M251 to the latest Firmware and perform reboot. | Update reference ↗ |
| CVE-2024-6528 | 11 Jul 2024 | All versions; All Versions | Modicon Controller M241 Firmware version 5.2.11.24 delivered with EcoStruxure™ Machine Expert v2.2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2.2 of EcoStruxure™ Machine Expert. Update Modicon Controller M241 to the latest Firmware and perform reboot | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.