CVE-2026-3869
Received Received - Intake

Incorrect Authentication in PLC Application Project

Vulnerability report for CVE-2026-3869, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Schneider Electric SE

Description

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-11
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
schneider_electric modicon_m580 From 4.00 (inc)
schneider_electric modicon_m580_safety From 4.20 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-3869 is a critical vulnerability in Schneider Electric's Modicon M580 and M580 Safety controllers due to incorrect implementation of the authentication algorithm. This flaw allows unauthenticated connections to the controllers, potentially leading to loss of confidentiality, integrity, and availability of the PLCs if exploited.

Detection Guidance

Detection of CVE-2026-3869 requires checking the firmware and application levels of Modicon M580 and M580 Safety controllers. Verify if the firmware is below version 4.10 for M580 or 4.21 for M580 Safety. Additionally, check if the application project levels are below 4.00 for M580 or 4.20 for M580 Safety. Use Schneider Electric's EcoStruxure Control Expert software to inspect these versions.

Impact Analysis

This vulnerability could allow attackers to gain unauthorized access to PLCs, leading to potential disruptions in industrial control systems. This may result in operational downtime, data breaches, or even physical damage to connected systems if exploited.

Compliance Impact

The vulnerability could lead to loss of confidentiality, integrity, and availability of PLCs, which may impact compliance with standards like GDPR and HIPAA by exposing sensitive data or disrupting critical operations. Unauthorized access to industrial control systems could result in data breaches or operational failures, violating regulatory requirements for data protection and system integrity.

Mitigation Strategies

Update firmware to version 4.10 or higher for Modicon M580 and 4.21 or higher for Modicon M580 Safety. Update application projects to levels 4.00 or 4.20 respectively. Use EcoStruxure Control Expert V15.2 or later for M580 and V16.0 with HF001 for M580 Safety.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3869. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart