CVE-2026-35227: Improper resource management in CODESYS Modbus TCP Server
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35227?
CVE-2026-35227 is classified as a high severity vulnerability due to its impact on the availability of the CODESYS Modbus TCP Server.
How do I fix CVE-2026-35227?
To mitigate CVE-2026-35227, update the CODESYS Modbus TCP Server to the latest version provided by the vendor.
What causes CVE-2026-35227?
CVE-2026-35227 is caused by improper resource management which leads to a race condition in TCP connection handling.
Can CVE-2026-35227 be exploited remotely?
Yes, CVE-2026-35227 can be exploited by unauthenticated remote attackers.
What is the potential impact of CVE-2026-35227?
The potential impact of CVE-2026-35227 is that it may exhaust all available TCP connections, preventing legitimate clients from connecting.