Vulnerabilities in openPLC
8 resultsVexday analysis
O openPLC apresenta footprint mínimo de vulnerabilidades na base Vexday com apenas 1 CVE registrado, sendo crítico em severidade, mas sem evidência de exploração ativa em ambiente real. A ausência de divulgações recentes (90+ dias) sugere risco estabilizado, embora o impacto potencial da vulnerabilidade crítica exija validação de cobertura nos ambientes que usam a plataforma.
CVE-2024-34026CRITICALA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248EPSS 2.4%CVE-2024-36980HIGHAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7EPSS 1.1%CVE-2024-39589HIGHMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3EPSS 1.0%CVE-2024-36981HIGHAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7EPSS 1.0%CVE-2024-39590HIGHMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3EPSS 1.0%CVE-2026-14480HIGHOpenPLC v3 External Control of File Name or PathEPSS 0.6%CVE-2025-53476MEDIUMA denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A spEPSS 0.5%CVE-2025-1066CRITICALCVE-2025-1066EPSS 0.5%