CVE-2026-102511
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host.
Leer descripción completaMostrar menos
Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.
Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.
This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.
Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution75 % - Impacto principal
T1557Adversary-in-the-Middlecredential access · collection85 % - Impacto secundario
T1499.004Application or System Exploitationimpact70 %
Requiere interacción del usuario (invocar discovery API, actuar sobre resultados). El atacante suplanta respuestas UDP (AV:A, UI:P) para redirigir conexiones y DoS de listeners mediante datagramas malformados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-129, CWE-248, CWE-835, CWE-940
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-102511",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-102511",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-30T16:43:37.289772Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security@apache.org",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.5,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security@apache.org",
"affectedData": [
{
"vendor": "Apache Software Foundation",
"product": "Apache PLC4X",
"versions": [
{
"status": "affected",
"version": "0.11.0",
"lessThan": "1.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
],
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"packageName": "github.com/apache/plc4x/plc4go",
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected"
},
{
"vendor": "Apache Software Foundation",
"product": "Apache PLC4X",
"versions": [
{
"status": "affected",
"version": "0.10.0",
"lessThan": "1.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
],
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-ads",
"packageName": "org.apache.plc4x:plc4j-driver-ads",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
},
{
"vendor": "Apache Software Foundation",
"product": "Apache PLC4X",
"versions": [
{
"status": "affected",
"version": "0.10.0",
"lessThan": "1.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
],
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-modbus",
"packageName": "org.apache.plc4x:plc4j-driver-modbus",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
},
{
"vendor": "Apache Software Foundation",
"product": "Apache PLC4X",
"versions": [
{
"status": "affected",
"version": "0.11.0",
"lessThan": "1.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
],
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-eip",
"packageName": "org.apache.plc4x:plc4j-driver-eip",
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-30T09:17:14.467",
"references": [
{
"url": "https://lists.apache.org/thread.html/g692j4fklrbo80stjr5ll8xghrwszthf",
"source": "security@apache.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/30/7",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security@apache.org",
"description": [
{
"lang": "en",
"value": "CWE-129"
},
{
"lang": "en",
"value": "CWE-248"
},
{
"lang": "en",
"value": "CWE-835"
},
{
"lang": "en",
"value": "CWE-940"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection \naddress was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\nwill open its ADS session, including any configured route credentials, to that host.\n\nAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\n- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\n- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\n- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\n\nExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\n\nThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it."
}
],
"lastModified": "2026-09-30T17:16:40.860",
"sourceIdentifier": "security@apache.org"
}