PT-2026-103084 · Apache Plc4X · Plc4J+1
CVSS v4.0
8.5
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Apache PLC4X PLC4Go versions 0.11.0 through 0.9.9
Apache PLC4X PLC4J ADS and Modbus drivers versions 0.10.0 through 0.9.9
Apache PLC4X PLC4J EtherNet/IP driver versions 0.11.0 through 0.9.9
Description
Improper verification of the communication channel source in the ADS discovery of the Go implementation (PLC4Go) allows an attacker to send UDP datagrams to a discovering host to redirect subsequent connections to an arbitrary address. This occurs because the connection address is derived from the
AmsNetId claimed in the response body instead of the actual source address of the datagram. Consequently, a spoofed response can insert an inventory entry pointing to any host, causing applications to send ADS sessions and route credentials to the attacker-controlled address.Additionally, discovery listeners can be disabled via malformed datagrams:
- In PLC4Go ADS discovery, a short version block triggers a panic that terminates the listener.
- In PLC4J, the ADS and EtherNet/IP discoverers stop due to unhandled exceptions from malformed responses.
- The PLC4J Modbus discoverer may enter an infinite loop, consuming a CPU core, when receiving a partial response from a scanned host.
Exploitation requires the application to use the opt-in discovery API and act upon the discovered items.
Recommendations
Upgrade PLC4Go to version 1.0.0.
Upgrade PLC4J ADS and Modbus drivers to version 1.0.0.
Upgrade PLC4J EtherNet/IP driver to version 1.0.0.
Fix
Infinite Loop
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plc4Go
Plc4J