PatchSiren cyber security CVE debrief
CVE-2018-7853 Schneider Electric CVE debrief
CVE-2018-7853 is a denial-of-service vulnerability in Schneider Electric Modicon M580 firmware. According to the advisory, an uncaught exception can occur when the controller reads invalid physical memory blocks over Modbus, which can disrupt controller availability. The source advisory was originally published on 2019-05-14 and later revised with updated remediation guidance.
- Vendor
- Schneider Electric
- Product
- Modicon M580 Firmware Versions prior to v2.90 installed on Modicon M580 Controller
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2019-05-14
- Original CVE updated
- 2026-04-23
- Advisory published
- 2019-05-14
- Advisory updated
- 2026-04-23
Who should care
OT security teams, PLC engineers, plant operators, and asset owners running Schneider Electric Modicon M580 controllers or managing EcoStruxure Control Expert projects should care most. This is especially important where Modbus/TCP is reachable from plant or enterprise networks.
Technical summary
The advisory states that Modicon M580 firmware versions prior to v2.90 are affected when invalid physical memory blocks are read over Modbus, causing an uncaught exception and denial of service. Schneider Electric’s remediation guidance includes updating the engineering workstation to EcoStruxure Control Expert v16.0, updating the controller to M580 firmware SV4.20 or above, rebuilding and retransferring projects, and applying defensive controls such as application passwords, network segmentation, ACLs, port 502/TCP filtering, secured communications, and memory protection where applicable.
Defensive priority
High
Recommended defensive actions
- Upgrade Modicon M580 controller firmware to SV4.20 or above, as directed in the vendor remediation guidance.
- Update EcoStruxure Control Expert to v16.0 before rebuilding and transferring controller projects.
- Set an application password in project properties and rebuild/retransfer affected projects.
- Restrict and segment OT network access; block unauthorized access to Modbus/TCP port 502 where feasible.
- Review and apply Schneider Electric ACL and secure communications guidance, including IPsec options where supported.
- Enable M580 CPU memory protection where applicable, noting the advisory’s limitation for Hot Standby CPUs.
Evidence notes
The key evidence comes from the Schneider Electric/CISA advisory and the linked vendor notice. The advisory describes an uncaught exception that can cause denial of service when reading invalid physical memory blocks in the controller over Modbus, and it scopes affected M580 firmware to versions prior to v2.90. The remediation text explicitly calls for firmware SV4.20 or above, EcoStruxure Control Expert v16.0, and defensive measures including application passwords, segmentation, ACLs, secured communications, and memory protection. The source record also includes a CVSS v4.0 base score of 8.7 (High) and a CVSS v3.1 vector, so the scoring metadata should be read carefully alongside the advisory text.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-7853 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-7853
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-7853 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-7853
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.