CVE-2025-1400
Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.
if the function tries to unpack a malformed EtherNet/IP network packet, then it occurs a memory leak in the target process.
May 6, 2025
This issue affects libplctag from 2.0 through 2.6.3
CVE-2025-1400
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
3.1
To fix this issue, it's suggested to update libplctag to v2.6.4
Gabriele Quagliarella of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

