PT-2026-103084 · Apache Plc4X · Plc4J+1

·

CVE-2026-102511

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Apache PLC4X PLC4Go versions 0.11.0 through 0.9.9 Apache PLC4X PLC4J ADS and Modbus drivers versions 0.10.0 through 0.9.9 Apache PLC4X PLC4J EtherNet/IP driver versions 0.11.0 through 0.9.9
Description Improper verification of the communication channel source in the ADS discovery of the Go implementation (PLC4Go) allows an attacker to send UDP datagrams to a discovering host to redirect subsequent connections to an arbitrary address. This occurs because the connection address is derived from the AmsNetId claimed in the response body instead of the actual source address of the datagram. Consequently, a spoofed response can insert an inventory entry pointing to any host, causing applications to send ADS sessions and route credentials to the attacker-controlled address.
Additionally, discovery listeners can be disabled via malformed datagrams:
  • In PLC4Go ADS discovery, a short version block triggers a panic that terminates the listener.
  • In PLC4J, the ADS and EtherNet/IP discoverers stop due to unhandled exceptions from malformed responses.
  • The PLC4J Modbus discoverer may enter an infinite loop, consuming a CPU core, when receiving a partial response from a scanned host.
Exploitation requires the application to use the opt-in discovery API and act upon the discovered items.
Recommendations Upgrade PLC4Go to version 1.0.0. Upgrade PLC4J ADS and Modbus drivers to version 1.0.0. Upgrade PLC4J EtherNet/IP driver to version 1.0.0.

Fix

Infinite Loop

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102511

Affected Products

Plc4Go
Plc4J