Impact
The vulnerability is an improper verification of the source of a communication channel within the ADS discovery process of Apache PLC4X’s Go implementation. An attacker who can send UDP datagrams to a host that invokes the discovery API can craft a spoofed ADS discovery response. The discovery logic incorrectly derives the target address for a subsequent ADS session from the claimed AmsNetId in the response rather than from the datagram’s source IP. This flaw allows the attacker to redirect the application’s ADS session to an arbitrary, attacker‑chosen address, potentially including hosts outside the local network. If the application uses route credentials, the attacker can gain privileged access to the target PLC or other industrial control device, leading to unauthorized command execution or broader compromise. In addition to the hijacking risk, the flaw can be leveraged for denial‑of‑service or resource exhaustion: a malformed datagram can cause a panic in PLC4Go, stop the discovery listener in PLC4J, or spin the Modbus discoverer forever, consuming CPU and disrupting normal discovery operations.
Affected Systems
The affected products are Apache PLC4X components: PLC4Go (Go implementation) and PLC4J (Java implementation). PLC4Go is vulnerable from version 0.11.0 through 0.99.x. PLC4J’s ADS and Modbus drivers are vulnerable from 0.10.0 through 0.99.x, while the EtherNet/IP driver is vulnerable from 0.11.0 through 0.99.x. All affected releases are bundled in the Apache PLC4X 0.11.x–0.99.x series, which in turn are distributed as the Go module github.com/apache/plc4x/plc4go for Go users and as the Java libraries for PLC4J users.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and although an EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits yet. The attack vector is network‑based: an attacker must be able to reach the host that performs ADS discovery and send crafted UDP packets. Successful exploitation requires that the application explicitly invokes the discovery API, which is optional but widely used for device enumeration. Once triggered, the attacker can hijack subsequent ADS sessions and potentially gain control over remote PLCs, and can also cause denial‑of‑service by terminating the discovery listener or exhausting CPU resources.
OpenCVE Enrichment