CVE-2026-0667
Awaiting Analysis Awaiting Analysis - Queue

Improper Check for Unusual Conditions in Modbus TCP Protocol

Vulnerability report for CVE-2026-0667, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: Schneider Electric SE

Description

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a CWE-754 vulnerability affecting Modbus TCP protocol communication. It involves improper handling of unusual or exceptional conditions, which could lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity in affected systems.

Impact Analysis

The vulnerability may allow attackers to execute arbitrary code, disrupt services via denial of service, or steal and alter sensitive data during Modbus TCP communications, potentially affecting system availability and data security.

Compliance Impact

This vulnerability could lead to breaches of confidentiality and integrity, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information, potentially resulting in compliance failures and penalties.

Mitigation Strategies

Implement strict input validation for Modbus TCP communications and ensure all devices are updated to the latest firmware versions to address improper exception handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0667. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart