PatchSiren cyber security CVE debrief
CVE-2018-7855 Schneider Electric CVE debrief
CVE-2018-7855 is a Schneider Electric Modicon controller vulnerability in which invalid breakpoint parameters sent over Modbus can trigger an uncaught exception and denial of service. The supplied advisory marks it as a high-severity availability issue and lists multiple affected Modicon families, with some legacy Quantum and Premium products receiving mitigation guidance rather than a fix.
- Vendor
- Schneider Electric
- Product
- Modicon M580 Firmware Versions prior to v4.20 installed on Modicon M580 Controller (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2019-05-14
- Original CVE updated
- 2026-04-23
- Advisory published
- 2019-05-14
- Advisory updated
- 2026-04-23
Who should care
Industrial control system operators, OT security teams, and control engineers responsible for Schneider Electric Modicon M580, M340, MC80, Momentum Unity M1E, Quantum, Quantum Safety, and Premium environments should care, especially where Modbus/TCP is reachable or EcoStruxure Control Expert workstations manage the controllers.
Technical summary
The source advisory describes an uncaught exception reachable by sending invalid breakpoint parameters to the controller over Modbus, resulting in denial of service and loss of availability. The CSAF advisory lists affected firmware and controller families across Modicon M580, M340, MC80, Momentum Unity M1E, Quantum/Quantum Safety, and Premium product lines; for some end-of-life Quantum and Premium products, Schneider Electric states no fix is planned and recommends mitigation and migration.
Defensive priority
High. The issue is network-reachable over Modbus and can disrupt controller availability in operational environments, so supported systems should be patched promptly and exposed systems should be protected with compensating controls.
Recommended defensive actions
- Update supported Modicon M580 systems to firmware SV4.20 or later and EcoStruxure Control Expert to v16.0, then rebuild and transfer projects as instructed by the vendor.
- Update supported Modicon M340 systems to firmware v3.60 or later and apply the vendor's project update/rebuild/transfer steps.
- Update supported Modicon Momentum Unity M1E systems to firmware v2.90 or later and the referenced EcoStruxure Control Expert version, then rebuild and transfer projects.
- For Quantum, Quantum Safety, and Premium systems, apply the vendor mitigations immediately and plan migration where the advisory says no fix is planned.
- Restrict Modbus/TCP access to port 502 with network segmentation, firewalls, and ACLs; use application passwords and secure communication options described in the vendor guidance.
- After any firmware change, verify the controller firmware version in projects and rebuild/transfer to align the engineering workstation with the target controller.
Evidence notes
The supplied corpus states: "An uncaught exception vulnerability exists, which could cause a denial of service when sending invalid breakpoint parameters to the controller over Modbus." The advisory publication timestamp is 2019-05-14, and later source revisions appear in the timeline through 2020; the source modified timestamp is 2026-04-23. The corpus also contains a CVSS v4.0 base score of 8.7 (High) in the advisory description, while the metadata section includes a CVSS 3.1 vector with a 7.5 score, so the supplied scoring fields are inconsistent; this debrief follows the advisory's described high-availability impact and affected-product guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-7855 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-7855
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-7855 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-7855
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/ww/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.