Out-of-bounds Read in libplctag library

CVE-2025-1400

Summary

Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

Impact

if the function tries to unpack a malformed EtherNet/IP network packet, then it occurs a memory leak in the target process.

Issue Date

May 6, 2025

Affects

This issue affects libplctag from 2.0 through 2.6.3

CVE Name

CVE-2025-1400

CVSS Details

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CVSS Score

3.1

Solution

To fix this issue, it's suggested to update libplctag to v2.6.4

Mitigations

Acknowledgements

Gabriele Quagliarella of Nozomi Networks

Nozomi Threat Intelligence

Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.

Learn more

Latest Labs Blogs

Iranian APT Activity During Geopolitical Escalation: Recommendations for Nozomi Customers and Critical Infrastructure Owners

Read

Detecting New OT Threats: How To Do It Proactively 

Read

Smile, You’re Being Hacked: Nozomi Networks Labs Finds Five New Flaws in Hanwha Wisenet Cameras

Read
View All

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.