目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-102511— Apache PLC4X ADS发现响应欺骗漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache PLC4X
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Apache PLC4X 的 Go 实现(PLC4Go)中,ADS 发现机制存在“通信通道来源验证不当”的漏洞。能够向执行发现的 host 发送 UDP 数据报的攻击者,可以将后续连接重定向到任意由攻击者指定的地址。发现结果中的连接地址是从响应体中声称的 AmsNetId 派生出来的,而非来自数据报的实际源地址。因此,一个伪造的发现响应可以插入一条指向任意主机(包括本地网络之外的主机)的设备清单条目。如果应用程序连接到已发现的设备,它将向该攻击者指定的主机建立 ADS 会话,并可能泄露其中配置的路由凭据。 此外,两

CVSS 8.5 · High

可能的 ATT&CK 技术 1 AI

T1566 · Phishing
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-102511 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them
来源: CVE Program / CVE List V5
Vulnerability Description
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host. Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response. Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items. This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
通信信道源的不正确验证
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache PLC4X 0.11.0 ~ 1.0.0 -
Apache Software Foundation Apache PLC4X 0.10.0 ~ 1.0.0 -
Apache Software Foundation Apache PLC4X 0.10.0 ~ 1.0.0 -
Apache Software Foundation Apache PLC4X 0.11.0 ~ 1.0.0 -

二、漏洞 CVE-2026-102511 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-102511 的情报信息

请登录查看更多情报信息。

CVE-2026-102511 邮件列表归档 (1)

同批安全公告 · Apache Software Foundation · 2026-09-30 · 共 19 条

CVE-2026-102508 9.2 CRITICAL Apache PLC4X OPC UA 安全通道完整性绕过漏洞
CVE-2026-94053 9.1 CRITICAL Apache MINA SSHD LDAP注入漏洞
CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD LDAP认证失效漏洞
CVE-2026-77185 9.1 CRITICAL Apache MINA SSHD 异步认证绕过签名验证漏洞
CVE-2026-102510 8.7 HIGH Apache PLC4X Go绑定远程内存耗尽漏洞
CVE-2026-102509 8.7 HIGH Apache PLC4X OPC UA驱动认证前资源耗尽漏洞
CVE-2026-93994 8.1 HIGH Apache MINA SSHD 公钥策略绕过漏洞
CVE-2026-94002 7.5 HIGH Apache MINA SSHD 内存耗尽漏洞
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD 远程代码执行漏洞
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD 内存耗尽拒绝服务漏洞
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD SFTP内存耗尽漏洞
CVE-2026-88920 Apache WSS4J SAML身份验证绕过漏洞
CVE-2026-87830 Apache WSS4J 流式验证跳过元素保护检查漏洞
CVE-2026-85532 Apache WSS4J 派生密钥参数验证不足漏洞
CVE-2026-89238 Apache WSS4J 加密头混淆致错误保护
CVE-2026-95616 Apache WSS4J 整数溢出拒绝服务漏洞
CVE-2026-92121 Apache WSS4J 签名检查绕过漏洞
CVE-2026-92899 Apache WSS4J 用户名令牌重放保护绕过漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-102511

暂无评论


发表评论