PatchSiren cyber security CVE debrief
CVE-2018-7843 Schneider Electric CVE debrief
CVE-2018-7843 is a Schneider Electric Modicon controller denial-of-service issue caused by an uncaught exception when the device reads memory blocks with an invalid data size or invalid data offset over Modbus. The supplied advisory record shows the issue was publicly disclosed on 2019-05-14 and later revised multiple times, mainly to refine remediation guidance. While the primary label is Modicon M580, the advisory scope also includes Modicon M340, Quantum, and Premium product lines. The impact is availability-only: no evidence in the supplied sources indicates code execution or data disclosure.
- Vendor
- Schneider Electric
- Product
- Modicon M580 Controller
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2019-05-14
- Original CVE updated
- 2026-04-23
- Advisory published
- 2019-05-14
- Advisory updated
- 2026-04-23
Who should care
Operators, integrators, and defenders responsible for Schneider Electric Modicon PLCs and related engineering workstations, especially environments that expose Modbus/TCP (port 502) or rely on M580, M340, Quantum, or Premium controllers.
Technical summary
The flaw is an uncaught exception in Modbus handling when a memory-block read request contains invalid size or offset values. In the supplied advisory, Schneider Electric ties fixes to specific firmware releases: Modicon M580 SV4.20 or above, Modicon M340 v3.60 or above, Modicon Quantum v3.60, and Modicon Premium v3.20. The advisory also recommends compensating controls such as application passwords, network segmentation, ACLs, and blocking unauthorized access to port 502/TCP.
Defensive priority
High priority for any exposed or remotely reachable Modicon controller, because the issue can be triggered over the network and directly affects availability.
Recommended defensive actions
- Update affected firmware to the vendor-fixed release for the relevant controller family (M580 SV4.20+, M340 v3.60+, Quantum v3.60, Premium v3.20).
- Update EcoStruxure Control Expert/project settings to match the target controller firmware, then rebuild and transfer the project as directed by the vendor.
- Restrict Modbus/TCP exposure: block unauthorized access to port 502/TCP, segment networks, and apply controller ACL guidance from the vendor manuals.
- Configure application passwords in project properties where supported.
- Use vendor-recommended secure communications and, where applicable, IPsec or external firewall/VPN protections described in the advisory.
- For end-of-life Quantum and Premium systems, plan migration to supported platforms rather than relying only on compensating controls.
Evidence notes
The source corpus states: an uncaught exception can cause denial of service when reading memory blocks with an invalid data size or invalid data offset over Modbus. The advisory metadata and remediation entries list affected Schneider Electric product families and fixed firmware versions, plus mitigations centered on application passwords, segmentation, ACLs, and blocking unauthorized access to port 502/TCP. The revision history shows the notice was updated several times after the original 2019-05-14 publication, including corrections to remediation/version information. The supplied CVE summary uses a CVSS v3.1 vector/score of 7.5 HIGH, while the description also includes a CVSS v4.0 8.7 HIGH string; both are present in the source corpus and should not be conflated.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-7843 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-7843
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-7843 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-7843
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.