PT-2026-103083 · Apache · Apache Plc4X
CVE-2026-102510
·
Published
2026-09-30
·
Updated
2026-09-30
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache PLC4X versions 0.11.0 through 0.13.1
Description
The Go implementation of Apache PLC4X (PLC4Go) contains multiple flaws including integer overflow, improper validation of array indices, uncontrolled recursion, and memory allocation with excessive size values. These issues allow a malicious device or an attacker capable of injecting network traffic to cause a denial of service by crashing the client application or exhausting its memory. Specifically, generated parsers pre-allocate arrays based on element counts claimed on the wire, and transport read helpers allocate buffers without an upper bound. Additionally, ADS and KNXnet/IP response handling fails to check data length before indexing, leading to a panic. ADS and EIP frame-length handling may accept or wrap to a length of zero, disrupting message framing. Furthermore, recursive protocol types are parsed without a nesting-depth limit. Length and position arithmetic in generated serializers using 16-bit integers can cause the length field to wrap when payloads exceed 8 KB, potentially leading the receiving device to interpret the remainder of the payload as independent protocol messages.
Recommendations
Upgrade to version 1.0.0.
Fix
Uncontrolled Recursion
Integer Overflow
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Plc4X