A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Modicon M340 Subscribe
Modicon M340 Firmware Subscribe
Modicon M580 Subscribe
Modicon M580 Firmware Subscribe
Modicon Premium Subscribe
Modicon Premium Firmware Subscribe
Modicon Quantum Subscribe
Modicon Quantum Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 29 May 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-248
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-05-29T14:20:22.410Z

Reserved: 2018-03-08T00:00:00.000Z

Link: CVE-2018-7852

cve-icon Vulnrichment

Updated: 2024-08-05T06:37:59.655Z

cve-icon NVD

Status : Modified

Published: 2019-05-22T20:29:01.900

Modified: 2026-05-29T15:16:17.330

Link: CVE-2018-7852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses