CVE-2018-8872: Schneider Electric Triconex Tricon Mp 3008 Firmware

High severity, CVSS 8.1. EPSS: 2.2% chance of exploitation in the next 30 days.

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

Affected products

Published 2018-05-04. Last modified 2026-06-17.