---
id: CVE-2025-13901
title: >-
  CWE-404 Improper Resource Shutdown or Release vulnerability exists that could
  cause partial Denial of Service on Machine Expert protocol when an
  unauthenticated attacker sends malicious payload to occupy active
  communication channels.
summary: >-
  CWE-404 Improper Resource Shutdown or Release vulnerability exists that could
  cause partial Denial of Service on Machine Expert protocol when an
  unauthenticated attacker sends malicious payload to occupy active
  communication channels.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
published: '2026-03-10'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13901'
references:
  - url: >-
      https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-01.pdf
    label: cybersecurity@se.com
tags:
  - nvd
epss: 0.00455
epssPercentile: 0.36974
ingestedAt: '2026-06-29T13:24:34.795Z'
---

## Overview

CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
