PT-2025-41853 · Ups · Ups

Published

2025-10-14

·

Updated

2025-10-19

·

CVE-2025-41703

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions UPS (affected versions not specified)
Description An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via a Modbus command. This disruption can lead to power outages or equipment shutdowns. The vulnerability allows for the disruption of normal UPS operation, potentially causing serious operational consequences. The attack is performed using a Modbus command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-41703

Affected Products

Ups