CVE-2011-4861
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware upd...
Affects 3 products across 1 vendor.
Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.
The Schneider Electric Quantum Ethernet Module (NOE 771) contains a vulnerability in the modbus_125_handler function that allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502. This vulnerability has a CVSS score of 10.0, indicating critical severity, but the exploitation likelihood is low due to the lack of public proof-of-concept and exploits.
BSID: BS-2011-GLOBAL-316555-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2011-4861?
What is the CVSS score for CVE-2011-4861?
Is CVE-2011-4861 actively exploited?
How do I remediate CVE-2011-4861?
What systems are affected by CVE-2011-4861?
What NERC-CIP standard applies to CVE-2011-4861?
What IEC 62443 requirement maps to CVE-2011-4861?
| CVE ID | CVE-2011-4861 |
|---|---|
| BSID | BS-2011-GLOBAL-316555-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2011-12-17 |
| Last Modified | 2026-04-29 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502.
Source: NIST NVD / MITRE CVE Database
Remote attackers can exploit the modbus_125_handler function by sending a MODBUS 125 function code to TCP port 502, which allows them to install arbitrary firmware updates on the affected device. This can lead to complete control over the device, including potential denial of service, data corruption, and unauthorized access to the control system.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Schneider-Electric | Quantum Ethernet Module 140Noe77100 | — |
| Schneider-Electric | Quantum Ethernet Module 140Noe77101 | — |
| Schneider-Electric | Quantum Ethernet Module 140Noe77111 | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation and access controls to restrict communication to the affected device only from trusted sources. Monitor traffic to TCP port 502 for suspicious activity.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to the control system, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 because it involves a vulnerability that could allow an attacker to perform unauthorized changes to the firmware of the device, which is a critical security concern in ICS environments.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | c64e68e2272112175378fd799297116bc411736837650ce193a0591be018cded205c62bca7736a53e11cbe8c1e63032686243dca84aff5e1c3a5ff631a0e7ece |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →