peter bassill · operator
$ cve CVE-2018-7842 JSON

CVE-2018-7842

9.8
CRITICAL · CVSS 3.1 · EPSS 35% (pctl 98)

Patch early

EPSS 35% — above the 10% action threshold.

Description

A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS35.04% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-290
On CISA KEVno
Public exploitnone known
Published2019-05-22
Last modified2026-06-17

Affected (8)

VendorProduct
schneider-electricmodicon m340
schneider-electricmodicon m340 firmware
schneider-electricmodicon m580
schneider-electricmodicon m580 firmware
schneider-electricmodicon premium
schneider-electricmodicon premium firmware
schneider-electricmodicon quantum
schneider-electricmodicon quantum firmware

References

→ the Explorer  ·  watch your stack  ·  NVD