CVE-2026-35225: Improper timeout handling in CODESYS EtherNetIP
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35225?
The severity of CVE-2026-35225 is classified as high due to its potential to disrupt legitimate communications by exhausting TCP connections.
How do I fix CVE-2026-35225?
To fix CVE-2026-35225, apply the latest security patch provided by CODESYS for the EtherNet/IP adapter stack.
Who is affected by CVE-2026-35225?
CVE-2026-35225 affects users of the CODESYS EtherNet/IP adapter stack, particularly those running vulnerable versions.
What are the potential impacts of CVE-2026-35225?
The potential impacts of CVE-2026-35225 include denial of service as legitimate clients are unable to establish new TCP connections.
Is CVE-2026-35225 exploitable remotely?
Yes, CVE-2026-35225 can be exploited remotely by unauthenticated attackers, making it a significant threat.