Christofer Dutz

#33549of 57,671
8.5Total CVSS
Vulnerabilities · 1
PT-2026-103084
8.5
2026-09-30
Apache Plc4X · Plc4J · CVE-2026-102511
**Name of the Vulnerable Software and Affected Versions** Apache PLC4X PLC4Go versions 0.11.0 through 0.9.9 Apache PLC4X PLC4J ADS and Modbus drivers versions 0.10.0 through 0.9.9 Apache PLC4X PLC4J EtherNet/IP driver versions 0.11.0 through 0.9.9 **Description** Improper verification of the communication channel source in the ADS discovery of the Go implementation (PLC4Go) allows an attacker to send UDP datagrams to a discovering host to redirect subsequent connections to an arbitrary address. This occurs because the connection address is derived from the `AmsNetId` claimed in the response body instead of the actual source address of the datagram. Consequently, a spoofed response can insert an inventory entry pointing to any host, causing applications to send ADS sessions and route credentials to the attacker-controlled address. Additionally, discovery listeners can be disabled via malformed datagrams: - In PLC4Go ADS discovery, a short version block triggers a panic that terminates the listener. - In PLC4J, the ADS and EtherNet/IP discoverers stop due to unhandled exceptions from malformed responses. - The PLC4J Modbus discoverer may enter an infinite loop, consuming a CPU core, when receiving a partial response from a scanned host. Exploitation requires the application to use the opt-in discovery API and act upon the discovered items. **Recommendations** Upgrade PLC4Go to version 1.0.0. Upgrade PLC4J ADS and Modbus drivers to version 1.0.0. Upgrade PLC4J EtherNet/IP driver to version 1.0.0.