VYPR

OpenPLC

by Openplcproject

Source repositories

CVEs (11)

  • CVE-2024-34026CriSep 18, 2024
    risk 0.59cvss 9.0epss 0.02

    A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of…

  • CVE-2021-47770HigJan 21, 2026
    risk 0.57cvss 8.8epss 0.01

    OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that…

  • CVE-2024-39590HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of…

  • CVE-2024-39589HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of…

  • CVE-2024-36981HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP…

  • CVE-2024-36980HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP…

  • CVE-2025-34226HigOct 3, 2025
    risk 0.46cvss epss 0.01

    OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime…

  • CVE-2026-31156MedMay 13, 2026
    risk 0.35cvss 6.5epss 0.00

    A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are…

  • CVE-2024-37741MedJun 28, 2024
    risk 0.35cvss 5.4epss 0.00

    OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.

  • CVE-2021-3351MedAug 2, 2021
    risk 0.35cvss 5.4epss 0.01

    OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.

  • CVE-2025-53476MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to the server not processing subsequent Modbus requests. An attacker can open a…