PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-7843 Schneider Electric CVE debrief

CVE-2018-7843 is a Schneider Electric Modicon controller denial-of-service issue caused by an uncaught exception when the device reads memory blocks with an invalid data size or invalid data offset over Modbus. The supplied advisory record shows the issue was publicly disclosed on 2019-05-14 and later revised multiple times, mainly to refine remediation guidance. While the primary label is Modicon M580, the advisory scope also includes Modicon M340, Quantum, and Premium product lines. The impact is availability-only: no evidence in the supplied sources indicates code execution or data disclosure.

Vendor
Schneider Electric
Product
Modicon M580 Controller
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2019-05-14
Original CVE updated
2026-04-23
Advisory published
2019-05-14
Advisory updated
2026-04-23

Who should care

Operators, integrators, and defenders responsible for Schneider Electric Modicon PLCs and related engineering workstations, especially environments that expose Modbus/TCP (port 502) or rely on M580, M340, Quantum, or Premium controllers.

Technical summary

The flaw is an uncaught exception in Modbus handling when a memory-block read request contains invalid size or offset values. In the supplied advisory, Schneider Electric ties fixes to specific firmware releases: Modicon M580 SV4.20 or above, Modicon M340 v3.60 or above, Modicon Quantum v3.60, and Modicon Premium v3.20. The advisory also recommends compensating controls such as application passwords, network segmentation, ACLs, and blocking unauthorized access to port 502/TCP.

Defensive priority

High priority for any exposed or remotely reachable Modicon controller, because the issue can be triggered over the network and directly affects availability.

Recommended defensive actions

  • Update affected firmware to the vendor-fixed release for the relevant controller family (M580 SV4.20+, M340 v3.60+, Quantum v3.60, Premium v3.20).
  • Update EcoStruxure Control Expert/project settings to match the target controller firmware, then rebuild and transfer the project as directed by the vendor.
  • Restrict Modbus/TCP exposure: block unauthorized access to port 502/TCP, segment networks, and apply controller ACL guidance from the vendor manuals.
  • Configure application passwords in project properties where supported.
  • Use vendor-recommended secure communications and, where applicable, IPsec or external firewall/VPN protections described in the advisory.
  • For end-of-life Quantum and Premium systems, plan migration to supported platforms rather than relying only on compensating controls.

Evidence notes

The source corpus states: an uncaught exception can cause denial of service when reading memory blocks with an invalid data size or invalid data offset over Modbus. The advisory metadata and remediation entries list affected Schneider Electric product families and fixed firmware versions, plus mitigations centered on application passwords, segmentation, ACLs, and blocking unauthorized access to port 502/TCP. The revision history shows the notice was updated several times after the original 2019-05-14 publication, including corrections to remediation/version information. The supplied CVE summary uses a CVSS v3.1 vector/score of 7.5 HIGH, while the description also includes a CVSS v4.0 8.7 HIGH string; both are present in the source corpus and should not be conflated.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-7843 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-7843

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-7843 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-7843

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.