Impact
A denial‑of‑service vulnerability exists in the receive loop of libmodbus 3.1.12 when executed on Windows. The flaw results from improper handling of timeout values during network read operations, allowing a remote attacker to send crafted Modbus traffic that keeps the library waiting for a response that never arrives. The library blocks indefinitely or consumes excessive resources, ultimately rendering the service unavailable to legitimate users. The weak point is a resource‑management defect leading to unbounded waiting and potential exhaustion of server capacity.
Affected Systems
The vulnerability affects systems running libmodbus version 3.1.12 on the Windows platform. No specific vendor or product name is documented in the CNA metadata, so any deployment of this library edition on Windows is potentially impacted. Version information for other releases has not been provided, so it is unknown whether newer or older releases are affected.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS base score of 7.5 reflects a high severity for denial‑of‑service. Given the description, the attack vector is inferred to be network‑based, requiring an attacker to transmit malicious Modbus packets to a target host running a Modbus service built with libmodbus 3.1.12 on Windows. The impact is the loss of availability for that service, which could affect critical industrial control or other operational systems that rely on Modbus communication.
OpenCVE Enrichment