These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CISA published ICSA-26-076-01 on 2026-02-26 and republished the vendor advisory on 2026-03-17. The advisory describes a stack-based out-of-bounds write in the CmpTraceMgr component used by multiple CODESYS products. In affected Festo Automation Suite/CODESYS combinations, an authenticated remote attacker could corrupt stack memory, causing denial of service, memory overwriting, or potentially remote code execution.
CVE-2018-7841 affects Schneider Electric U.motion Builder and is identified by CISA as a known exploited vulnerability. The CISA KEV entry describes the issue as a SQL injection vulnerability and notes that the impacted product is end-of-life and should be disconnected if still in use. Because it appears in the KEV catalog, defenders should treat it as urgent even though the source corpus does not provide [truncated]
A CWE-287 Improper Authentication vulnerability in Schneider Electric PowerLogic PM55xx series power meters allows unauthenticated attackers to disrupt Modbus TCP connectivity by sending specially crafted HTTP requests. The vulnerability affects PM5560, PM5561, PM5562, and PM5563 models with specific firmware versions, plus the end-of-service PM8ECC. Vendor fixes were released between 2021 and 2024, with [truncated]
CVE-2021-22763 is a HIGH severity vulnerability (CVSS 3.1: 8.1) in Schneider Electric PowerLogic PM55xx series power meters and PM8ECC communication modules. The weakness (CWE-640: Weak Password Recovery Mechanism for Forgotten Password) allows an unauthenticated attacker to gain administrator-level access to affected devices. Originally published on 2021-06-08, the advisory was updated on 2024-11-12 to n [truncated]
CVE-2019-6830 is a Schneider Electric Modicon M580 controller vulnerability where an uncaught exception can lead to a possible denial of service if the controller receives an appropriately timed HTTP request. The primary security impact is loss of availability in an OT environment, not code execution or data theft. The supplied CISA advisory and vendor notice recommend upgrading the controller to SV4.20 o [truncated]
CVE-2019-6829 is a Schneider Electric controller vulnerability where a Modbus write to certain memory addresses can trigger an uncaught exception and potentially deny service on affected Modicon controllers. The issue is documented for Modicon M580 firmware prior to v2.90 and Modicon M340 firmware prior to v3.10 in the source advisory, with vendor remediation guidance also pointing to newer fixed firmware [truncated]
CVE-2019-6808 is a critical improper access control issue in Schneider Electric Modicon controllers. According to the supplied advisory material, an attacker could overwrite controller configuration settings over Modbus and potentially achieve remote code execution. Schneider Electric and CISA guidance ties the issue to multiple Modicon families, with firmware updates available for some products and migra [truncated]
CVE-2019-6807 is an uncaught-exception flaw in Schneider Electric Modicon products that can lead to a denial of service when sensitive application variables are written to a controller over Modbus. The advisory covers multiple Modicon families, and the safest response is to apply the vendor’s fixed firmware/software for the exact platform and harden Modbus exposure while upgrading.
CVE-2019-6806 is a confidentiality issue in Schneider Electric Modicon controllers where reading controller variables over Modbus can disclose SNMP information. The advisory scope is broader than the M580 controller named in the title: the supplied source corpus also lists M340, Quantum, Quantum Safety, and Premium product families. The practical risk is highest where Modbus is reachable outside a trusted [truncated]
CVE-2018-7856 affects Schneider Electric Modicon controller families where malformed Modbus writes to invalid memory blocks can trigger an uncaught exception and denial of service. The vendor and CISA source material treat this as a network-reachable operational risk, with fixes and mitigations spanning firmware updates, application passwords, segmentation, ACLs, and restricted Modbus/TCP exposure.
CVE-2018-7855 is a Schneider Electric Modicon controller vulnerability in which invalid breakpoint parameters sent over Modbus can trigger an uncaught exception and denial of service. The supplied advisory marks it as a high-severity availability issue and lists multiple affected Modicon families, with some legacy Quantum and Premium products receiving mitigation guidance rather than a fix.
CVE-2018-7854 is a Schneider Electric Modicon controller denial-of-service issue caused by an uncaught exception when invalid debug parameters are sent to the controller over Modbus. The advisory ties the issue to Modicon M580 firmware versions prior to v2.90 and Modicon M340 firmware versions prior to v3.10, with vendor fixes later available in M580 SV4.20 and M340 v3.60. Because the vulnerable path is r [truncated]
CVE-2018-7853 is a denial-of-service vulnerability in Schneider Electric Modicon M580 firmware. According to the advisory, an uncaught exception can occur when the controller reads invalid physical memory blocks over Modbus, which can disrupt controller availability. The source advisory was originally published on 2019-05-14 and later revised with updated remediation guidance.
A network-reachable denial-of-service issue affects multiple Schneider Electric Modicon controller lines. According to the vendor and CISA advisory material in the source corpus, sending an invalid private command parameter over Modbus can trigger an uncaught exception in the controller and disrupt availability. The supplied record was published on 2019-05-14, and later advisory revisions clarified affect [truncated]
CVE-2018-7850 is a Schneider Electric industrial control system vulnerability where untrusted inputs were relied on in a security decision, which could cause invalid information to be displayed in Unity Pro software. The supplied advisory data ties the issue to multiple Modicon controller families, not just the M580 title product, and provides fixes for some lines while leaving end-of-life products on mit [truncated]
CVE-2018-7849 affects Schneider Electric Modicon controller families and can lead to a denial of service when files are sent to the controller over Modbus. The source advisory describes the root cause as an uncaught exception tied to an improper data integrity check. For some product lines, fixed firmware is available; for end-of-life lines, Schneider Electric recommends migration and network mitigations.
CVE-2018-7848 is an information exposure issue in Schneider Electric Modicon controllers where reading files from the controller over Modbus could disclose SNMP information. The public advisory and CSAF material identify firmware fixes for some platforms and recommend network segmentation, access control, and application-password protections for exposed OT environments.
CVE-2018-7846 affects Schneider Electric Modicon controller families and is described by the advisory as a trust boundary violation on connection to the controller that could enable unauthorized access through brute-force attempts against the Modbus protocol. The core defensive takeaway is straightforward: where vendor fixes exist, upgrade firmware and the engineering workstation software, then update and [truncated]
CVE-2018-7845 is an information-disclosure flaw in Schneider Electric Modicon controllers. The advisory says an out-of-bounds read while reading specific memory blocks over Modbus can expose unexpected controller data. Schneider Electric and CISA published the advisory on 2019-05-14, with later revisions adding remediation details for multiple Modicon product lines.
CVE-2018-7844 is an information exposure issue in Schneider Electric Modicon controller ecosystems. According to the advisory, reading memory blocks from affected controllers over Modbus could disclose SNMP information. The risk is highest in networks where Modbus services are reachable across insufficiently segmented OT or enterprise environments, especially on port 502/TCP. Schneider Electric’s guidance [truncated]
CVE-2018-7843 is a Schneider Electric Modicon controller denial-of-service issue caused by an uncaught exception when the device reads memory blocks with an invalid data size or invalid data offset over Modbus. The supplied advisory record shows the issue was publicly disclosed on 2019-05-14 and later revised multiple times, mainly to refine remediation guidance. While the primary label is Modicon M580, t [truncated]
CVE-2018-7842 is an authentication-bypass-by-spoofing issue affecting Schneider Electric Modicon controllers and related firmware. The advisory says an attacker could brute-force Modbus parameters sent to the controller and gain elevated privilege. Schneider Electric provides firmware fixes for some affected lines, while Quantum, Quantum Safety, and Premium products are end-of-life and rely on mitigation [truncated]
CVE-2016-5815 is a critical access-control weakness in several Schneider Electric ION-series power meters. According to NVD, authentication is not configured by default, allowing an unauthorized user to access the device management portal and make configuration changes. The issue is associated with multiple ION product families used in operational environments, so exposure of the management interface can [truncated]
CVE-2016-5809 is a cross-site request forgery weakness in several Schneider Electric ION power meter families. According to the NVD record and the ICS-CERT advisory reference, the affected devices do not generate a CSRF token to authenticate the user during a session, which can let an attacker induce unauthorized configuration changes that are then saved. NVD rates the issue HIGH with CVSS 8.8.
CVE-2017-5155 affects Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. The NVD record and referenced vendor/ICS-CERT advisories state that Wonderware Historian creates logins with default passwords, which can let a malicious entity compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may also be compromised. The supplied [truncated]
CVE-2017-5157 is a cross-site scripting (CWE-79) issue affecting Schneider Electric homeLYnk Controller LSS100100 firmware versions before V1.5.0. According to the CVE description, user inputs can be manipulated to trigger JavaScript execution. NVD rates the issue CVSS 3.0 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N), indicating network reachability and required user interaction, with limited confidentiality [truncated]
CVE-2016-8374 is a high-severity denial-of-service issue affecting multiple Schneider Electric Magelis HMI product families. The weakness is described as uncontrolled resource consumption in a targeted web server, allowing a remote attacker to disrupt availability without authentication or user interaction.
CVE-2016-8367 describes a denial-of-service condition in several Schneider Electric Magelis panel firmware families. A remote attacker can open multiple connections to the targeted web server and leave them open, which can block new connections and make the web server unavailable during the attack. The CVE was published on 2017-02-13 and is rated CVSS 3.1 5.3 MEDIUM in the supplied record.
CVE-2016-8354 describes a code-execution flaw in Schneider Electric Unity PRO where Unity projects compiled as x86 instructions can be loaded into the bundled PLC Simulator and executed directly. A specially crafted patched Unity project file can redirect control flow so the simulator runs malicious code. The issue was published on 2017-02-13 and is associated with Unity PRO versions prior to V11.1, with [truncated]
CVE-2016-8352 is a critical Schneider Electric ConneXium firewall vulnerability published on 2017-02-13. According to the official record, a stack-based buffer overflow in the SNMP login authentication process can allow remote code execution. The NVD entry rates the issue CVSS 10.0 with network attack vector, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.