CVE-2018-7842
9.8
CRITICAL · CVSS 3.1 · EPSS 35% (pctl 98)
Patch early
EPSS 35% — above the 10% action threshold.
Description
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 35.04% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-290 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-05-22 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| schneider-electric | modicon m340 |
| schneider-electric | modicon m340 firmware |
| schneider-electric | modicon m580 |
| schneider-electric | modicon m580 firmware |
| schneider-electric | modicon premium |
| schneider-electric | modicon premium firmware |
| schneider-electric | modicon quantum |
| schneider-electric | modicon quantum firmware |
References
→ the Explorer · watch your stack · NVD