CVE-2018-7846
9.8
CRITICAL · CVSS 3.1 · EPSS 29.6% (pctl 98)
Patch early
EPSS 29.6% — above the 10% action threshold.
Description
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 29.58% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-668 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-05-22 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| schneider-electric | modicon m340 |
| schneider-electric | modicon m340 firmware |
| schneider-electric | modicon m580 |
| schneider-electric | modicon m580 firmware |
| schneider-electric | modicon premium |
| schneider-electric | modicon premium firmware |
| schneider-electric | modicon quantum |
| schneider-electric | modicon quantum firmware |
References
→ the Explorer · watch your stack · NVD