Impact
A buffer overflow exists in the pcpp::ModbusLayer::getLength function of the Modbus protocol handler in PcapPlusPlus. Manipulating the length argument causes a heap‑based overflow, potentially allowing an attacker to overwrite memory and gain arbitrary code execution. The flaw is triggered by remote network traffic and the vulnerability is classified as high complexity and difficult to exploit, yet public exploit code has already been released.
Affected Systems
seladb PcapPlusPlus 25.05 is affected. The flaw resides in the ModbusLayer.h component of the library. Installing the patch identified by commit 4c90c3e3418a2b09dc82b7ca5775e9c1e22fe454 resolves the issue.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score is not available. The vulnerability is not listed in CISA KEV. An attacker can potentially launch the attack remotely, but success requires non‑trivial effort and knowledge of the Modbus payload. Publicly available exploit code increases the risk of real‑world attacks. During this period, vulnerability exploitation is considered difficult but not impossible.
OpenCVE Enrichment