Tec Nikan
فارسی
Talk to us
All news

Two Fixes for One Flaw on the M580

Schneider Electric has disclosed a CVSS 9.8 authentication-algorithm flaw in Modicon M580 and M580 Safety controllers, and remediating it needs both a firmware update and a raised application level.

Schneider ElectricModicon M580PLC securityCVE-2026-3869IEC 62443

Schneider Electric issued security notification SEVD-2026-251-04 on 8 September, covering CVE-2026-3869 — an incorrect implementation of an authentication algorithm, CWE-303 — in the Modicon M580 Ethernet-based programmable automation controller and the M580 Safety variant. The CVSS v3.1 base score is 9.8, with a vector of network attack, low complexity, no privileges and no user interaction, giving high impact to confidentiality, integrity and availability; under CVSS v4.0 it scores 9.2. The M580 is affected in all versions running an application project below application level 4.00, and the M580 Safety in all versions below application level 4.20. Schneider warns that failure to remediate risks an unauthenticated connection being established to the controller. Remediation is two-part: for the M580, firmware 4.10 or above together with an application level of 4.00 or above, available from EcoStruxure Control Expert V15.2 or later; for the M580 Safety, firmware 4.21 or above with application level 4.20, requiring Control Expert V16.0 with HF001. The finder is credited as a Schneider Electric partner.

The detail that makes this advisory unusual — and that will cause the most trouble in practice — is that the firmware update alone does not fix it. The application level is a property of the project running on the controller, not of the controller, so remediation requires opening the project in a specific version of the engineering tool, raising its level, recompiling and downloading it. That is a controller stop on most sites, which means a planned outage, a change request, and re-validation of anything safety-related. It is a different class of work from pushing a firmware image, and a maintenance window booked on the assumption of the latter will not be long enough.

There is a second-order consequence worth flagging for anyone running a fleet of these. Raising an application level changes the project format, and a project saved at the higher level may no longer open in the older engineering tool. Any site where several people hold Control Expert at different versions, or where an integrator maintains the project on their own machine, needs the tool versions aligned before the first controller is touched — otherwise the result is a plant with two project formats and no single person able to edit all of them.

The immediate mitigations are the ordinary ones and they are effective here because the attack is over the network: the M580's control network should not be reachable from the business network or the internet, remote access should be through a controlled path rather than a forwarded port, and the controller's Ethernet services that are not in use should be disabled. A CVSS 9.8 with no privileges required is precisely the profile that makes network exposure the whole question, and most M580 installations will find that the honest answer to how reachable the controller is depends on a firewall rule somebody wrote for a commissioning task years ago.

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.