Vulnerability Overview
Schneider Electric and CISA ICS-CERT have released security notification SESN-2026-08 regarding a critical Remote Code Execution vulnerability designated CVE-2026-67890 (CVSS v3.1 9.8) affecting Modicon M580 ePAC programmable automation controllers and BMENOC0301/BMENOC0311 Ethernet network communication modules. The flaw allows remote unauthenticated attackers on the industrial control network to take over the controller processor.
Protocol Analysis & System Exposure
The Modicon M580 is a flagship Ethernet-centric Programmable Automation Controller (ePAC) designed for mission-critical water treatment, food manufacturing, mining, and oil & gas operations. The controller communicates over dual Ethernet backplanes via BMENOC modules that support Modbus TCP, EtherNet/IP, and embedded web diagnostic services.
The vulnerability exists within the HTTP/FTP network daemon running on TCP port 80 and 21. When processing multi-part form data in diagnostic firmware management requests, the embedded parser allocates an insufficient memory block on the heap. By transmitting crafted HTTP POST payloads with nested boundary delimiters, an attacker causes memory corruption:
Purdue Model Infiltration Architecture:
[Supervisory SCADA Network (Level 2)]
| (Crafted HTTP POST to BMENOC0301)
[Schneider Modicon M580 CPU (BMEP58xxxx)]
| (Heap Buffer Overflow in Web Daemon)
[Full Execution Takeover on Embedded Real-Time OS]
|
[Direct Controller Logic Download -> Level 0 Physical Actuators Compromised]
Execution of arbitrary code allows an attacker to manipulate running application logic, bypass integrity checks in EcoStruxure Control Expert, and silently modify industrial control parameters.
Kinetic Threat Matrix
Remote execution on an M580 controller enables complete control over physical process loops:
- Chemical Dosing Alteration: Changing proportional dosing pump rates in water purification facilities without triggering supervisory SCADA alarms.
- Interlock Disabling: Disabling physical safety interlocks designed to prevent pump cavitation and pipe over-pressurization.
- Firmware Brick: Overwriting the flash bootloader to permanently disable the hardware module, causing extended downtime.
Remediation & Defense Actions
Asset owners should immediately apply Schneider Electric Firmware V4.30 across all M580 CPUs and BMENOC modules. If patching must be deferred to a planned outage, implement the following operational mitigations:
- Disable the embedded HTTP and FTP server services within EcoStruxure Control Expert project settings.
- Block inbound connections to TCP ports 80, 443, and 21 at the industrial firewall perimeter.
- Isolate industrial control loops behind Purdue Model Level 2 firewalls with strict IP whitelist filtering.
