PT-2026-49133 · Unknown · Nanomodbus
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
nanoMODBUS versions prior to 1.23.1
Description
The Modbus/TCP server contains an off-by-one buffer overflow in the
recv msg header() function. Remote unauthenticated attackers can exploit this by sending a crafted MBAP frame with the Length field set to 255, allowing them to write one controlled byte beyond the end of the 260-byte receive buffer. This action corrupts the buffer-index field of the nanoMODBUS state structure, which can lead to a denial of service due to invalid memory accesses. On bare-metal and RTOS (Real-Time Operating System) targets lacking memory protection, this may also result in the disclosure of one byte of information and unauthorized writes to register addresses within the Write Multiple Registers (FC16) handler path.Recommendations
Update nanoMODBUS to a version later than 1.23.0.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nanomodbus