CVE-2025-53476: Medium severity OpenPLC OpenPLC vulnerability
A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to the server not processing subsequent Modbus requests. An attacker can open a series of TCP connections to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53476?
CVE-2025-53476 is classified as a denial of service vulnerability.
How do I fix CVE-2025-53476?
To mitigate CVE-2025-53476, it is advised to update to the latest version of OpenPLC that resolves this issue.
What is the impact of CVE-2025-53476?
The impact of CVE-2025-53476 involves the ModbusTCP server becoming unable to process any subsequent Modbus requests.
Which software versions are affected by CVE-2025-53476?
CVE-2025-53476 affects OpenPLC versions prior to the update addressing this vulnerability.
Can CVE-2025-53476 be exploited remotely?
Yes, CVE-2025-53476 can be exploited remotely through specially crafted series of network connections.