CVE-2025-53476
A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to the server not processing subsequent Modbus requests. An attacker can open a series of TCP connections to trigger this vulnerability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.46%
- CWE
- CWE-775
- Published
- 2025-10-07
- Last modified
- 2026-03-13
Affected products
- OpenPLC OpenPLC_v3
Weakness type
Related vulnerabilities
- CVE-2026-78408 — Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
- CVE-2026-45287 — OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
- CVE-2019-25557 — TwistedBrush Pro Studio 24.06 Denial of Service via srp File
- CVE-2025-13751 — Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on...
- CVE-2017-8452 — Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be...