Apache PLC4X 的 Go 实现(PLC4Go)中,ADS 发现机制存在“通信通道来源验证不当”的漏洞。能够向执行发现的 host 发送 UDP 数据报的攻击者,可以将后续连接重定向到任意由攻击者指定的地址。发现结果中的连接地址是从响应体中声称的 AmsNetId 派生出来的,而非来自数据报的实际源地址。因此,一个伪造的发现响应可以插入一条指向任意主机(包括本地网络之外的主机)的设备清单条目。如果应用程序连接到已发现的设备,它将向该攻击者指定的主机建立 ADS 会话,并可能泄露其中配置的路由凭据。 此外,两
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X | 0.11.0< 1.0.0 |
affected |
1.0.0 |
unaffected | ||
0.10.0< 1.0.0 |
affected | ||
1.0.0 |
unaffected | ||
0.10.0< 1.0.0 |
affected | ||
1.0.0 |
unaffected | ||
0.11.0< 1.0.0 |
affected | ||
1.0.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache PLC4X | 0.11.0 ~ 1.0.0 | - |
|
| Apache Software Foundation | Apache PLC4X | 0.10.0 ~ 1.0.0 | - |
|
| Apache Software Foundation | Apache PLC4X | 0.10.0 ~ 1.0.0 | - |
|
| Apache Software Foundation | Apache PLC4X | 0.11.0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102508 | 9.2 CRITICAL | Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an |
| CVE-2026-94053 | 9.1 CRITICAL | Apache MINA SSHD: LDAP injection in sshd-ldap |
| CVE-2026-94052 | 9.1 CRITICAL | Apache MINA SSHD: LDAP password authentication ineffective |
| CVE-2026-77185 | 9.1 CRITICAL | Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
| CVE-2026-102510 | 8.7 HIGH | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len |
| CVE-2026-102509 | 8.7 HIGH | Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an |
| CVE-2026-93994 | 8.1 HIGH | Apache MINA SSHD: Repeated-publickey policy bypass on server |
| CVE-2026-94002 | 7.5 HIGH | Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies |
| CVE-2026-93995 | 6.5 MEDIUM | Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser |
| CVE-2026-93996 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read |
| CVE-2026-94029 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension |
| CVE-2026-88920 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | |
| CVE-2026-87830 | Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. | |
| CVE-2026-85532 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters | |
| CVE-2026-89238 | Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti | |
| CVE-2026-95616 | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5 | |
| CVE-2026-92121 | Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST | |
| CVE-2026-92899 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce |
No comments yet