Security readout for executives and security teams
Plain-English summary
This CVE affects Schneider Electric Modicon industrial controllers. The issue can let an unauthorized party attempt brute-force access over Modbus to the controller. For executives, the concern is unauthorized access to PLCs that may support critical operations, especially if controller networks are reachable from untrusted systems.
Executive priority
Treat this as a high-priority OT exposure review if affected controllers are in production or reachable beyond tightly controlled networks. Urgency depends on network reachability and operational criticality.
Technical view
CVE-2018-7846 is described as a CWE-501 trust boundary violation during connection to the controller. The affected products are all versions of Modicon M580, M340, Quantum, and Premium. The disclosed impact is unauthorized access through brute-force activity against Modbus protocol access to the controller.
Likely exposure
Exposure is most likely in OT environments running the listed Modicon controllers where Modbus/controller access is reachable from users, hosts, vendors, or networks that should not be trusted.
Exploitation context
The provided bundle does not show CISA KEV listing or active exploitation evidence. Public references identify a brute-force unauthorized-access scenario, but the bundle does not provide CVSS, observed exploitation, or confirmed exploit availability.
Researcher notes
Evidence in the bundle is limited: no CVSS, CPEs, patch details, or KEV status. The core issue is unauthorized access risk from brute-force activity across a trust boundary on Modbus controller connections.
Mitigation direction
- Review Schneider Electric advisory SEVD-2019-134-11 for official remediation guidance.
- Restrict Modbus and controller access to trusted OT management networks only.
- Remove direct internet or broad enterprise-network reachability to affected controllers.
- Monitor controller access attempts for repeated failures or unusual Modbus activity.
- Review credential and access-control practices for affected controller connections.
Validation and detection
- Inventory Modicon M580, M340, Quantum, and Premium controllers in OT networks.
- Confirm whether Modbus/controller interfaces are reachable from untrusted or unnecessary network segments.
- Check logs or monitoring for repeated failed controller access attempts.
- Compare controller versions and configuration against Schneider Electric’s advisory guidance.
- Document compensating controls where vendor remediation cannot be immediately applied.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-7846 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/CVE reference · x_refsource_MISC
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0735CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
