Vulnerabilidades em OpenPLC
8 resultadosAnálise Vexday
OpenPLC apresenta 7 vulnerabilidades documentadas, sendo 1 crítica e nenhuma sob ataque ativo no momento. A fraqueza predominante é leitura fora dos limites (CWE-125), típica de software de controle industrial; o risco é moderado considerando a ausência de exploração ativa, mas merece atenção pois 1 CVE foi publicado nos últimos 90 dias.
CVE-2024-34026CRITICALA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d10248EPSS 2.4%CVE-2024-36980HIGHAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7EPSS 1.1%CVE-2024-39589HIGHMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3EPSS 1.0%CVE-2024-36981HIGHAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f7EPSS 1.0%CVE-2024-39590HIGHMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a3EPSS 1.0%CVE-2026-14480HIGHOpenPLC v3 External Control of File Name or PathEPSS 0.4%CVE-2025-1066CRITICALCVE-2025-1066EPSS 0.4%CVE-2025-53476MEDIUMA denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A spEPSS 0.3%