VYPR

PLC4J

by Apache

CVEs (3)

  • CVE-2026-102508CriSep 30, 2026
    risk 0.60cvss —epss —

    Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel…

  • CVE-2026-102509HigSep 30, 2026
    risk 0.50cvss —epss —

    Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial…

  • CVE-2026-102511HigSep 30, 2026
    risk 0.48cvss —epss —

    Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address.…