PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-7853 Schneider Electric CVE debrief

CVE-2018-7853 is a denial-of-service vulnerability in Schneider Electric Modicon M580 firmware. According to the advisory, an uncaught exception can occur when the controller reads invalid physical memory blocks over Modbus, which can disrupt controller availability. The source advisory was originally published on 2019-05-14 and later revised with updated remediation guidance.

Vendor
Schneider Electric
Product
Modicon M580 Firmware Versions prior to v2.90 installed on Modicon M580 Controller
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2019-05-14
Original CVE updated
2026-04-23
Advisory published
2019-05-14
Advisory updated
2026-04-23

Who should care

OT security teams, PLC engineers, plant operators, and asset owners running Schneider Electric Modicon M580 controllers or managing EcoStruxure Control Expert projects should care most. This is especially important where Modbus/TCP is reachable from plant or enterprise networks.

Technical summary

The advisory states that Modicon M580 firmware versions prior to v2.90 are affected when invalid physical memory blocks are read over Modbus, causing an uncaught exception and denial of service. Schneider Electric’s remediation guidance includes updating the engineering workstation to EcoStruxure Control Expert v16.0, updating the controller to M580 firmware SV4.20 or above, rebuilding and retransferring projects, and applying defensive controls such as application passwords, network segmentation, ACLs, port 502/TCP filtering, secured communications, and memory protection where applicable.

Defensive priority

High

Recommended defensive actions

  • Upgrade Modicon M580 controller firmware to SV4.20 or above, as directed in the vendor remediation guidance.
  • Update EcoStruxure Control Expert to v16.0 before rebuilding and transferring controller projects.
  • Set an application password in project properties and rebuild/retransfer affected projects.
  • Restrict and segment OT network access; block unauthorized access to Modbus/TCP port 502 where feasible.
  • Review and apply Schneider Electric ACL and secure communications guidance, including IPsec options where supported.
  • Enable M580 CPU memory protection where applicable, noting the advisory’s limitation for Hot Standby CPUs.

Evidence notes

The key evidence comes from the Schneider Electric/CISA advisory and the linked vendor notice. The advisory describes an uncaught exception that can cause denial of service when reading invalid physical memory blocks in the controller over Modbus, and it scopes affected M580 firmware to versions prior to v2.90. The remediation text explicitly calls for firmware SV4.20 or above, EcoStruxure Control Expert v16.0, and defensive measures including application passwords, segmentation, ACLs, secured communications, and memory protection. The source record also includes a CVSS v4.0 base score of 8.7 (High) and a CVSS v3.1 vector, so the scoring metadata should be read carefully alongside the advisory text.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-7853 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-7853

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-7853 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-7853

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.