Description
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection
address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices
will open its ADS session, including any configured route credentials, to that host.

Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram:
- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.
- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.
- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.

Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.

This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.

Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
Published: 2026-09-30
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via hijacked ADS connections
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper verification of the source of a communication channel within the ADS discovery process of Apache PLC4X’s Go implementation. An attacker who can send UDP datagrams to a host that invokes the discovery API can craft a spoofed ADS discovery response. The discovery logic incorrectly derives the target address for a subsequent ADS session from the claimed AmsNetId in the response rather than from the datagram’s source IP. This flaw allows the attacker to redirect the application’s ADS session to an arbitrary, attacker‑chosen address, potentially including hosts outside the local network. If the application uses route credentials, the attacker can gain privileged access to the target PLC or other industrial control device, leading to unauthorized command execution or broader compromise. In addition to the hijacking risk, the flaw can be leveraged for denial‑of‑service or resource exhaustion: a malformed datagram can cause a panic in PLC4Go, stop the discovery listener in PLC4J, or spin the Modbus discoverer forever, consuming CPU and disrupting normal discovery operations.

Affected Systems

The affected products are Apache PLC4X components: PLC4Go (Go implementation) and PLC4J (Java implementation). PLC4Go is vulnerable from version 0.11.0 through 0.99.x. PLC4J’s ADS and Modbus drivers are vulnerable from 0.10.0 through 0.99.x, while the EtherNet/IP driver is vulnerable from 0.11.0 through 0.99.x. All affected releases are bundled in the Apache PLC4X 0.11.x–0.99.x series, which in turn are distributed as the Go module github.com/apache/plc4x/plc4go for Go users and as the Java libraries for PLC4J users.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, and although an EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits yet. The attack vector is network‑based: an attacker must be able to reach the host that performs ADS discovery and send crafted UDP packets. Successful exploitation requires that the application explicitly invokes the discovery API, which is optional but widely used for device enumeration. Once triggered, the attacker can hijack subsequent ADS sessions and potentially gain control over remote PLCs, and can also cause denial‑of‑service by terminating the discovery listener or exhausting CPU resources.

Generated by OpenCVE AI on September 30, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Apache PLC4X to version 1.0.0 or later, which ensures that the ADS discovery derives the target address from the datagram’s source address and logs a warning when the claimed AmsNetId differs.
  • If the discovery API is not required, disable it or restrict its availability to trusted hosts only, thereby eliminating the attack surface.
  • Implement network monitoring to detect unexpected ADS connections or AmsNetId mismatches, and quarantine any host that receives unsolicited PDUs from unknown source IPs.

Generated by OpenCVE AI on September 30, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
References

Wed, 30 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache plc4x
Vendors & Products Apache
Apache plc4x

Wed, 30 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host. Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response. Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items. This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
Title Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
Weaknesses CWE-129
CWE-248
CWE-835
CWE-940
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-30T16:43:46.020Z

Reserved: 2026-09-29T11:41:47.734Z

Link: CVE-2026-102511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:14.467

Modified: 2026-09-30T16:14:10.347

Link: CVE-2026-102511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:30:18Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-248

    Uncaught Exception

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')

  • CWE-940

    Improper Verification of Source of a Communication Channel