Skip to main content

Threats Tagged 'ghsa-jfxw-f7pw-76rc'

View all threats tagged with 'ghsa-jfxw-f7pw-76rc'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: ghsa-jfxw-f7pw-76rc

Threats Tagged 'ghsa-jfxw-f7pw-76rc'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in the ADS discovery mechanism of Apache PLC4X's Go implementation (PLC4Go) and Java implementation (PLC4J) allows an attacker who can send UDP datagrams to the discovering host to redirect connections to arbitrary addresses. The issue arises because the connection address is derived from the claimed AmsNetId in the response body rather than the actual source address of the datagram. This can lead to an attacker inserting malicious inventory entries and intercepting ADS sessions with route credentials. Additionally, malformed datagrams can disrupt discovery listeners, causing them to stop or consume excessive CPU resources. The vulnerability affects versions prior to 1.0.0 and is fixed in version 1.0.0, which correctly derives connection addresses from the datagram source and logs warnings on mismatches.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: ghsa-jfxw-f7pw-76rc
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses