Back

CVE-2018-7846

CRITICAL

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.

Published: May 22, 2019 Modified: Jun 17, 2026
CWE-668

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
schneider-electric modicon_m580_firmware *
schneider-electric modicon_m340_firmware *
schneider-electric modicon_quantum_firmware *
schneider-electric modicon_premium_firmware *

GitHub Security Advisory GHSA-hvj5-x43r-qg3f

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 29.58%

Top 2% most likely to be exploited

Threat Score 48.1 / 100

Data Sources

NVD EPSS GitHub