CVE-2026-3869

Summary

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

Affected Software

VendorProductVersion RangeStatus
Schneider ElectricModicon M580All versions with an application level below 4.00affected
Schneider ElectricModicon M580 SafetyAll versions with an application level below 4.20affected

Weaknesses

  • CWE-303: CWE-303 Incorrect implementation of authentication algorithm

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References