Threats Tagged 'cve-2026-102511'
View all threats tagged with 'cve-2026-102511'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-102511'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in the ADS discovery mechanism of Apache PLC4X's Go implementation (PLC4Go) and Java implementation (PLC4J) allows an attacker who can send UDP datagrams to the discovering host to redirect connections to arbitrary addresses. The issue arises because the connection address is derived from the claimed AmsNetId in the response body rather than the actual source address of the datagram. This can lead to an attacker inserting malicious inventory entries and intercepting ADS sessions with route credentials. Additionally, malformed datagrams can disrupt discovery listeners, causing them to stop or consume excessive CPU resources. The vulnerability affects versions prior to 1.0.0 and is fixed in version 1.0.0, which correctly derives connection addresses from the datagram source and logs warnings on mismatches. Join the discussion | GCVE Database | 09/30/2026, 09:31:11 UTC Added: 09/30/2026, 15:53:29 UTC |
0 Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host. Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response. Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items. This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it. Join the discussion | CVE Database V5 | 09/30/2026, 08:03:04 UTC Added: 09/30/2026, 08:35:07 UTC |
Showing 1 to 2 of 2 results