CVE-2018-7853: High severity modicon premium firmware vulnerability
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7853?
CVE-2018-7853 is a vulnerability that affects all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium, which could cause a denial of service when reading invalid physical memory blocks in the controller over Modbus.
What is the severity of CVE-2018-7853?
CVE-2018-7853 has a severity rating of high with a value of 7.5.
How does CVE-2018-7853 affect Schneider-electric Modicon Premium Firmware?
Schneider-electric Modicon Premium Firmware is affected by CVE-2018-7853 and could be vulnerable to a denial of service when reading invalid physical memory blocks in the controller over Modbus.
How can I fix CVE-2018-7853?
To fix CVE-2018-7853, it is recommended to upgrade to a version of the Modicon M580, Modicon M340, Modicon Quantum, or Modicon Premium firmware that is not affected by the vulnerability.
Where can I find more information about CVE-2018-7853?
More information about CVE-2018-7853 can be found on the Schneider Electric website and Talos Intelligence's vulnerability report.