CVE-2026-3869
Received Received - Intake

Incorrect Authentication in PLC Application Project

Vulnerability report for CVE-2026-3869, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Schneider Electric SE

Description

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
schneider_electric modicon_m580 From 4.00 (inc)
schneider_electric modicon_m580_safety From 4.20 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-3869 is a critical vulnerability in Schneider Electric's Modicon M580 and M580 Safety controllers due to incorrect implementation of the authentication algorithm. This flaw allows unauthenticated connections to the controllers, potentially leading to loss of confidentiality, integrity, and availability of the PLCs if exploited.

Impact Analysis

This vulnerability could allow attackers to gain unauthorized access to PLCs, leading to potential disruptions in industrial control systems. This may result in operational downtime, data breaches, or even physical damage to connected systems if exploited.

Mitigation Strategies

Update firmware to version 4.10 or higher for Modicon M580 and 4.21 or higher for Modicon M580 Safety. Update application projects to levels 4.00 or 4.20 respectively. Use EcoStruxure Control Expert V15.2 or later for M580 and V16.0 with HF001 for M580 Safety.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3869. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart