Search
Find a vulnerability
Search criteria
10 vulnerabilities found for Apache PLC4X by Apache Software Foundation
CVE-2026-102511 (GCVE-0-2026-102511)
Vulnerability from nvd – Published: 2026-09-30 08:03 – Updated: 2026-09-30 16:43
VLAI
EPSS
VEX
Title
Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
Summary
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection
address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices
will open its ADS session, including any configured route credentials, to that host.
Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram:
- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.
- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.
- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.
Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.
This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.
Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:43 UTC
CWE
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.11.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.10.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-30T10:08:12.291Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/30/7"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102511",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:43:37.289772Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:43:46.020Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected",
"packageName": "github.com/apache/plc4x/plc4go",
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-ads",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-ads",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-modbus",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-modbus",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-eip",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-eip",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eImproper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result\u0027s connection \u003cbr\u003eaddress was derived from the AmsNetId claimed in the response body rather than from the datagram\u0027s actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\u003cbr\u003ewill open its ADS session, including any configured route credentials, to that host.\u003cbr\u003e\u003cbr\u003eAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\u003cbr\u003e- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\u003cbr\u003e- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\u003cbr\u003e- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\u003cbr\u003e\u003cbr\u003eExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram\u0027s source address and logs a warning when the claimed AmsNetId disagrees with it.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result\u0027s connection \naddress was derived from the AmsNetId claimed in the response body rather than from the datagram\u0027s actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\nwill open its ADS session, including any configured route credentials, to that host.\n\nAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\n- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\n- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\n- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\n\nExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\n\nThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram\u0027s source address and logs a warning when the claimed AmsNetId disagrees with it."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-940",
"description": "CWE-940 Improper Verification of Source of a Communication Channel (f054)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-129",
"description": "CWE-129 Improper Validation of Array Index (f053, f056 ADS)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-248",
"description": "CWE-248 Uncaught Exception (f053, f056: one bad datagram kills the listener)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-835",
"description": "CWE-835 Loop with Unreachable Exit Condition (f056 Modbus: the CPU spin)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:03:04.359Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/g692j4fklrbo80stjr5ll8xghrwszthf"
}
],
"source": {
"discovery": "INTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T12:22:00.000Z",
"value": "found during the internal security review"
},
{
"lang": "en",
"time": "2026-09-07T12:22:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102511",
"datePublished": "2026-09-30T08:03:04.359Z",
"dateReserved": "2026-09-29T11:41:47.734Z",
"dateUpdated": "2026-09-30T16:43:46.020Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102510 (GCVE-0-2026-102510)
Vulnerability from nvd – Published: 2026-09-30 08:01 – Updated: 2026-09-30 14:40
VLAI
EPSS
VEX
Title
Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Summary
Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,
causing a denial of service.
The individual defects are:
- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).
- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.
- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.
- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.
- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .
Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as
additional, independent protocol messages.
This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.
Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:40 UTC
CWE
- CWE-789 - Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)
- CWE-190 - Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)
- CWE-129 - Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)
- CWE-674 - Uncontrolled Recursion. This covers the Go part of f045
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/lw66k49p1jf7… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.11.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102510",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:40:24.270117Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:31.604Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected",
"packageName": "github.com/apache/plc4x/plc4go",
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eInteger Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\u003cbr\u003ecausing a denial of service.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\u003cbr\u003e- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\u003cbr\u003e- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\u003cbr\u003e- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102509\"\u003eCVE-2026-102509\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \u003cbr\u003eadditional, independent protocol messages.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-129",
"description": "CWE-129 Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the Go part of f045",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:01:43.024Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs"
}
],
"source": {
"discovery": "INTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T12:16:00.000Z",
"value": "found during the internal security review"
},
{
"lang": "en",
"time": "2026-09-07T12:17:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102510",
"datePublished": "2026-09-30T08:01:43.024Z",
"dateReserved": "2026-09-29T11:41:34.033Z",
"dateUpdated": "2026-09-30T14:40:31.604Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102509 (GCVE-0-2026-102509)
Vulnerability from nvd – Published: 2026-09-30 08:00 – Updated: 2026-09-30 14:40
VLAI
EPSS
VEX
Title
Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Summary
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.
In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can
impersonate it.
The individual defects are:
- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).
- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).
- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).
- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).
- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .
This issue affects Apache PLC4X: from 0.10.0 before 1.0.0.
Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:39 UTC
CWE
- CWE-789 - Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).
- CWE-770 - Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).
- CWE-674 - Uncontrolled Recursion. This covers the nested mspec types (f045).
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/qngc85qhnlj7… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.10.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102509",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:39:55.913450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:06.881Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-spi",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-spi",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-opcua",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-opcua",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abhinav Agarwal"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eMemory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\u003cbr\u003e\u003cbr\u003eIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \u003cbr\u003eimpersonate it.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\u003cbr\u003e- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102510\"\u003eCVE-2026-102510\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\n\nIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \nimpersonate it.\n\nThe individual defects are:\n- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\n- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\n- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\n- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .\n\nThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the nested mspec types (f045).",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:00:27.709Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/qngc85qhnlj7kpk3z58z0xlxhz2tn6gp"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-09T12:11:00.000Z",
"value": "reported to the Apache Security Team"
},
{
"lang": "en",
"time": "2026-07-10T12:11:00.000Z",
"value": "reported issues fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)"
},
{
"lang": "en",
"time": "2026-09-07T12:12:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102509",
"datePublished": "2026-09-30T08:00:27.709Z",
"dateReserved": "2026-09-29T11:41:21.875Z",
"dateUpdated": "2026-09-30T14:40:06.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102508 (GCVE-0-2026-102508)
Vulnerability from nvd – Published: 2026-09-30 07:42 – Updated: 2026-09-30 14:39
VLAI
EPSS
VEX
Title
Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
Summary
Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.
The defect manifests differently depending on the version:
- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password.
- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.
- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.
Users checking only for one of these mechanisms may wrongly conclude they are unaffected.
This issue affects Apache PLC4X: from 0.9.0 before 1.0.0.
Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the
connection if the negotiated security policy is weaker than the configured one.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:39 UTC
CWE
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.9.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-30T10:08:10.861Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/30/4"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102508",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:39:20.327319Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:39:33.687Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-opcua",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-opcua",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.9.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abhinav Agarwal"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eImproper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\u003cbr\u003e\u003cbr\u003eThe defect manifests differently depending on the version:\u003cbr\u003e- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user\u0027s password.\u003cbr\u003e- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\u003cbr\u003e- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\u003cbr\u003e\u003cbr\u003eUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\u003cbr\u003econnection if the negotiated security policy is weaker than the configured one.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\n\nThe defect manifests differently depending on the version:\n- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user\u0027s password.\n- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\n- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\n\nUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\n\nThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\nconnection if the negotiated security policy is weaker than the configured one."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper verification of cryptographic signature",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper Certificate Validation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-757",
"description": "CWE-757 Selection of Less-Secure Algorithm During Negotiation (\u0027Algorithm Downgrade\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:42:43.537Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/o076mcnsx6wnqpdy780m7s6hddbbnjfw"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-09T11:54:00.000Z",
"value": "reported to the Apache Security Team"
},
{
"lang": "en",
"time": "2026-07-10T11:55:00.000Z",
"value": "fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)"
},
{
"lang": "en",
"time": "2026-09-07T11:56:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fix"
}
],
"title": "Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102508",
"datePublished": "2026-09-30T07:42:43.537Z",
"dateReserved": "2026-09-29T11:40:54.414Z",
"dateUpdated": "2026-09-30T14:39:33.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2021-43083 (GCVE-0-2021-43083)
Vulnerability from nvd – Published: 2021-12-19 08:25 – Updated: 2024-08-04 03:47
VLAI
EPSS
VEX
Title
Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response
Summary
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.
Severity
No CVSS data available.
CWE
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/jxx6qc84z60xbbhn6… | x_refsource_MISC |
| http://www.openwall.com/lists/oss-security/2021/12/20/2 | mailing-listx_refsource_MLIST |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
PLC4C , ≤ 0.9.0
(custom)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T03:47:13.291Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7"
},
{
"name": "[oss-security] 20211220 CVE-2021-43083: Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2021/12/20/2"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "0.9.0",
"status": "affected",
"version": "PLC4C",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Apache PLC4X would like to thank Eugene Lim for reporting this issue."
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-119",
"description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-191",
"description": "CWE-191 Integer Underflow (Wrap or Wraparound)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2021-12-20T15:06:56.000Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7"
},
{
"name": "[oss-security] 20211220 CVE-2021-43083: Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2021/12/20/2"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"x_generator": {
"engine": "Vulnogram 0.0.9"
},
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "security@apache.org",
"ID": "CVE-2021-43083",
"STATE": "PUBLIC",
"TITLE": "Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Apache PLC4X",
"version": {
"version_data": [
{
"version_affected": "\u003c=",
"version_name": "PLC4C",
"version_value": "0.9.0"
}
]
}
}
]
},
"vendor_name": "Apache Software Foundation"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Apache PLC4X would like to thank Eugene Lim for reporting this issue."
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": [
{}
],
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer"
}
]
},
{
"description": [
{
"lang": "eng",
"value": "CWE-191 Integer Underflow (Wrap or Wraparound)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7",
"refsource": "MISC",
"url": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7"
},
{
"name": "[oss-security] 20211220 CVE-2021-43083: Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2021/12/20/2"
}
]
},
"source": {
"discovery": "UNKNOWN"
}
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2021-43083",
"datePublished": "2021-12-19T08:25:09.000Z",
"dateReserved": "2021-10-30T00:00:00.000Z",
"dateUpdated": "2024-08-04T03:47:13.291Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2026-102511 (GCVE-0-2026-102511)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:03 – Updated: 2026-09-30 16:43
VLAI
EPSS
VEX
Title
Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
Summary
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection
address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices
will open its ADS session, including any configured route credentials, to that host.
Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram:
- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.
- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.
- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.
Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.
This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.
Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:43 UTC
CWE
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.11.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.10.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-30T10:08:12.291Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/30/7"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102511",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:43:37.289772Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:43:46.020Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected",
"packageName": "github.com/apache/plc4x/plc4go",
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-ads",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-ads",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-modbus",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-modbus",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-eip",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-eip",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eImproper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result\u0027s connection \u003cbr\u003eaddress was derived from the AmsNetId claimed in the response body rather than from the datagram\u0027s actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\u003cbr\u003ewill open its ADS session, including any configured route credentials, to that host.\u003cbr\u003e\u003cbr\u003eAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\u003cbr\u003e- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\u003cbr\u003e- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\u003cbr\u003e- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\u003cbr\u003e\u003cbr\u003eExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram\u0027s source address and logs a warning when the claimed AmsNetId disagrees with it.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result\u0027s connection \naddress was derived from the AmsNetId claimed in the response body rather than from the datagram\u0027s actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\nwill open its ADS session, including any configured route credentials, to that host.\n\nAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\n- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\n- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\n- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\n\nExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\n\nThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram\u0027s source address and logs a warning when the claimed AmsNetId disagrees with it."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-940",
"description": "CWE-940 Improper Verification of Source of a Communication Channel (f054)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-129",
"description": "CWE-129 Improper Validation of Array Index (f053, f056 ADS)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-248",
"description": "CWE-248 Uncaught Exception (f053, f056: one bad datagram kills the listener)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-835",
"description": "CWE-835 Loop with Unreachable Exit Condition (f056 Modbus: the CPU spin)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:03:04.359Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/g692j4fklrbo80stjr5ll8xghrwszthf"
}
],
"source": {
"discovery": "INTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T12:22:00.000Z",
"value": "found during the internal security review"
},
{
"lang": "en",
"time": "2026-09-07T12:22:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102511",
"datePublished": "2026-09-30T08:03:04.359Z",
"dateReserved": "2026-09-29T11:41:47.734Z",
"dateUpdated": "2026-09-30T16:43:46.020Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102510 (GCVE-0-2026-102510)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:01 – Updated: 2026-09-30 14:40
VLAI
EPSS
VEX
Title
Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths
Summary
Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,
causing a denial of service.
The individual defects are:
- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).
- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.
- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.
- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.
- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .
Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as
additional, independent protocol messages.
This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.
Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:40 UTC
CWE
- CWE-789 - Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)
- CWE-190 - Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)
- CWE-129 - Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)
- CWE-674 - Uncontrolled Recursion. This covers the Go part of f045
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/lw66k49p1jf7… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.11.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102510",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:40:24.270117Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:31.604Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected",
"packageName": "github.com/apache/plc4x/plc4go",
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eInteger Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\u003cbr\u003ecausing a denial of service.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\u003cbr\u003e- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\u003cbr\u003e- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\u003cbr\u003e- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102509\"\u003eCVE-2026-102509\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \u003cbr\u003eadditional, independent protocol messages.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-129",
"description": "CWE-129 Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the Go part of f045",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:01:43.024Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs"
}
],
"source": {
"discovery": "INTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T12:16:00.000Z",
"value": "found during the internal security review"
},
{
"lang": "en",
"time": "2026-09-07T12:17:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102510",
"datePublished": "2026-09-30T08:01:43.024Z",
"dateReserved": "2026-09-29T11:41:34.033Z",
"dateUpdated": "2026-09-30T14:40:31.604Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102509 (GCVE-0-2026-102509)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:00 – Updated: 2026-09-30 14:40
VLAI
EPSS
VEX
Title
Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Summary
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.
In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can
impersonate it.
The individual defects are:
- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).
- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).
- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).
- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).
- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .
This issue affects Apache PLC4X: from 0.10.0 before 1.0.0.
Users are recommended to upgrade to version 1.0.0, which fixes the issue.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:39 UTC
CWE
- CWE-789 - Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).
- CWE-770 - Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).
- CWE-674 - Uncontrolled Recursion. This covers the nested mspec types (f045).
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/qngc85qhnlj7… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.10.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102509",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:39:55.913450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:06.881Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-spi",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-spi",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-opcua",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-opcua",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abhinav Agarwal"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eMemory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\u003cbr\u003e\u003cbr\u003eIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \u003cbr\u003eimpersonate it.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\u003cbr\u003e- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102510\"\u003eCVE-2026-102510\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\n\nIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \nimpersonate it.\n\nThe individual defects are:\n- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\n- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\n- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\n- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .\n\nThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the nested mspec types (f045).",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:00:27.709Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/qngc85qhnlj7kpk3z58z0xlxhz2tn6gp"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-09T12:11:00.000Z",
"value": "reported to the Apache Security Team"
},
{
"lang": "en",
"time": "2026-07-10T12:11:00.000Z",
"value": "reported issues fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)"
},
{
"lang": "en",
"time": "2026-09-07T12:12:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102509",
"datePublished": "2026-09-30T08:00:27.709Z",
"dateReserved": "2026-09-29T11:41:21.875Z",
"dateUpdated": "2026-09-30T14:40:06.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102508 (GCVE-0-2026-102508)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:42 – Updated: 2026-09-30 14:39
VLAI
EPSS
VEX
Title
Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
Summary
Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.
The defect manifests differently depending on the version:
- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password.
- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.
- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.
Users checking only for one of these mechanisms may wrongly conclude they are unaffected.
This issue affects Apache PLC4X: from 0.9.0 before 1.0.0.
Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the
connection if the negotiated security policy is weaker than the configured one.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:39 UTC
CWE
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.9.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-30T10:08:10.861Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/30/4"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102508",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:39:20.327319Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:39:33.687Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-opcua",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-opcua",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.9.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abhinav Agarwal"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eImproper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\u003cbr\u003e\u003cbr\u003eThe defect manifests differently depending on the version:\u003cbr\u003e- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user\u0027s password.\u003cbr\u003e- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\u003cbr\u003e- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\u003cbr\u003e\u003cbr\u003eUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\u003cbr\u003econnection if the negotiated security policy is weaker than the configured one.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\n\nThe defect manifests differently depending on the version:\n- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user\u0027s password.\n- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\n- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\n\nUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\n\nThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\nconnection if the negotiated security policy is weaker than the configured one."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper verification of cryptographic signature",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper Certificate Validation",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-757",
"description": "CWE-757 Selection of Less-Secure Algorithm During Negotiation (\u0027Algorithm Downgrade\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:42:43.537Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/o076mcnsx6wnqpdy780m7s6hddbbnjfw"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-09T11:54:00.000Z",
"value": "reported to the Apache Security Team"
},
{
"lang": "en",
"time": "2026-07-10T11:55:00.000Z",
"value": "fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)"
},
{
"lang": "en",
"time": "2026-09-07T11:56:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fix"
}
],
"title": "Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102508",
"datePublished": "2026-09-30T07:42:43.537Z",
"dateReserved": "2026-09-29T11:40:54.414Z",
"dateUpdated": "2026-09-30T14:39:33.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2021-43083 (GCVE-0-2021-43083)
Vulnerability from cvelistv5 – Published: 2021-12-19 08:25 – Updated: 2024-08-04 03:47
VLAI
EPSS
VEX
Title
Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response
Summary
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.
Severity
No CVSS data available.
CWE
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/jxx6qc84z60xbbhn6… | x_refsource_MISC |
| http://www.openwall.com/lists/oss-security/2021/12/20/2 | mailing-listx_refsource_MLIST |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
PLC4C , ≤ 0.9.0
(custom)
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T03:47:13.291Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7"
},
{
"name": "[oss-security] 20211220 CVE-2021-43083: Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"tags": [
"mailing-list",
"x_refsource_MLIST",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2021/12/20/2"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "0.9.0",
"status": "affected",
"version": "PLC4C",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Apache PLC4X would like to thank Eugene Lim for reporting this issue."
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-119",
"description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-191",
"description": "CWE-191 Integer Underflow (Wrap or Wraparound)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2021-12-20T15:06:56.000Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"x_refsource_MISC"
],
"url": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7"
},
{
"name": "[oss-security] 20211220 CVE-2021-43083: Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"tags": [
"mailing-list",
"x_refsource_MLIST"
],
"url": "http://www.openwall.com/lists/oss-security/2021/12/20/2"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"x_generator": {
"engine": "Vulnogram 0.0.9"
},
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "security@apache.org",
"ID": "CVE-2021-43083",
"STATE": "PUBLIC",
"TITLE": "Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Apache PLC4X",
"version": {
"version_data": [
{
"version_affected": "\u003c=",
"version_name": "PLC4C",
"version_value": "0.9.0"
}
]
}
}
]
},
"vendor_name": "Apache Software Foundation"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Apache PLC4X would like to thank Eugene Lim for reporting this issue."
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": [
{}
],
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer"
}
]
},
{
"description": [
{
"lang": "eng",
"value": "CWE-191 Integer Underflow (Wrap or Wraparound)"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7",
"refsource": "MISC",
"url": "https://lists.apache.org/thread/jxx6qc84z60xbbhn6vp2s5qf09psrtc7"
},
{
"name": "[oss-security] 20211220 CVE-2021-43083: Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response",
"refsource": "MLIST",
"url": "http://www.openwall.com/lists/oss-security/2021/12/20/2"
}
]
},
"source": {
"discovery": "UNKNOWN"
}
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2021-43083",
"datePublished": "2021-12-19T08:25:09.000Z",
"dateReserved": "2021-10-30T00:00:00.000Z",
"dateUpdated": "2024-08-04T03:47:13.291Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}