Critical severity9.8NVD Advisory· Published May 22, 2019· Updated Jun 17, 2026
CVE-2018-7847
CVE-2018-7847
Description
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- cpe:2.3:o:schneider-electric:modicon_m340_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:modicon_premium_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:schneider-electric:modicon_premium_firmware:*:*:*:*:*:*:*:*
- (no CPE)
- cpe:2.3:o:schneider-electric:modicon_quantum_firmware:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- www.talosintelligence.com/vulnerability_reports/TALOS-2018-0742nvdExploitThird Party Advisory
- www.schneider-electric.com/en/download/document/SEVD-2019-134-11/nvdVendor Advisory
- www.talosintelligence.com/vulnerability_reports/TALOS-2018-0743nvdThird Party Advisory
News mentions
0No linked articles in our index yet.