PT-2025-20019 · Libplctag · Libplctag
Gabriele Quagliarella
·
Published
2025-05-07
·
Updated
2025-05-07
·
CVE-2025-1400
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
libplctag versions 2.0 through 2.6.3
Description
The issue is related to an Out-of-bounds Read in the
unpack response function, located in conn.c, which allows Overread Buffers via the network. This can be exploited to potentially access sensitive information.Recommendations
For libplctag versions 2.0 through 2.6.3, consider restricting network access to the
unpack response function in conn.c until a patch is available. As a temporary workaround, limiting the use of the unpack response function can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libplctag