Impact
The vulnerability resides in the Go binding (PLC4Go) of Apache PLC4X and involves several improper validation issues: integer overflows in 16‑bit length calculations, unbounded allocation of arrays and buffers based on values supplied on the wire, out‑of‑bounds indexing into received data, and unrestrained recursive parsing of protocol types. These flaws allow an attacker who can inject or influence network traffic to cause the client application to crash or exhaust its memory, resulting in a denial‑of‑service condition. The weaknesses correspond to CWE‑129, CWE‑190, CWE‑674 and CWE‑789.
Affected Systems
Affected components are the Apache PLC4X project, specifically the Go binding (PLC4Go) consumed as the Go module github.com/apache/plc4x/plc4go. Vulnerable versions span from 0.11.0 up through releases prior to 1.0.0, including the 0.13.0 and 0.13.1 releases. Systems that use older PLC4Go versions and parse PLC traffic from devices such as ADS or KNXnet/IP can be impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS value is not available, suggesting that publicly available exploitation data is lacking but not that the risk is minimal. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is remote, via crafted PLC protocol messages that an attacker can send to a client application that is actively communicating with a PLC or similar device. If an attacker can inject such traffic—either from the same network or by compromising a connected PLC—he can trigger the unbounded allocations or arithmetic overflows, forcing the client to consume excessive memory or crash. There is no evidence that the flaw requires local privileges or access to privileged credentials; the exploit can be performed by any attacker who can deliver the malformed packets to the target client.
OpenCVE Enrichment