CVE-2025-41724

7.5

Sauter · modulo 6 and EY-modulo 5 devices

An unauthenticated remote attacker can cause a denial of service on Sauter modulo 6 and EY-modulo 5 devices by sending incomplete SOAP requests that crash the wscserver process.

Executive summary

A critical vulnerability in Sauter industrial control devices allows unauthenticated remote attackers to trigger a permanent service crash, requiring a manual device reboot to restore functionality.

Vulnerability

This flaw is classified as a failure to handle incomplete elements (CWE-239), where the wscserver fails to process malformed or incomplete SOAP requests. An unauthenticated attacker can exploit this via the network to force the server into a non-responsive state that lacks automatic recovery.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a significant risk to system availability. Because the wscserver does not automatically restart after the crash, affected systems experience a complete loss of function, which necessitates manual intervention or a physical reboot. In an industrial or building management environment, this could lead to operational downtime and disruptions to critical infrastructure services.

Remediation

Immediate Action: Update all affected Sauter devices to the latest firmware versions as specified in the manufacturer security advisory to resolve the handling of malformed SOAP requests.

Proactive Monitoring: Monitor network traffic for unusual or malformed SOAP requests directed at the wscserver and inspect system logs for service termination events.

Compensating Controls: Deploy network segmentation to restrict access to device management interfaces and utilize a Web Application Firewall (WAF) or industrial protocol gateway to filter and sanitize incoming SOAP traffic.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for operational disruption, organizations utilizing the affected Sauter hardware should prioritize the deployment of the provided firmware updates. Ensure that all devices are isolated from untrusted networks to minimize the attack surface until patches can be applied across the environment.

Sources

Originally found and disclosed by Damian Pfammatter, Daniel Hulliger from Cyber-Defence Campus armasuisse S+T, per the CVE Program record.