peter bassill · operator
$ cve CVE-2018-7846 JSON

CVE-2018-7846

9.8
CRITICAL · CVSS 3.1 · EPSS 29.6% (pctl 98)

Patch early

EPSS 29.6% — above the 10% action threshold.

Description

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS29.58% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-668
On CISA KEVno
Public exploitnone known
Published2019-05-22
Last modified2026-06-17

Affected (8)

VendorProduct
schneider-electricmodicon m340
schneider-electricmodicon m340 firmware
schneider-electricmodicon m580
schneider-electricmodicon m580 firmware
schneider-electricmodicon premium
schneider-electricmodicon premium firmware
schneider-electricmodicon quantum
schneider-electricmodicon quantum firmware

References

→ the Explorer  ·  watch your stack  ·  NVD