An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
History

Tue, 12 May 2026 07:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
Title Improper resource management in CODESYS Modbus TCP Server
First Time appeared Codesys
Codesys codesys Modbus
Weaknesses CWE-772
CPEs cpe:2.3:a:codesys:codesys_modbus:*:*:*:*:*:*:*:*
Vendors & Products Codesys
Codesys codesys Modbus
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-12T07:14:41.517Z

Reserved: 2026-04-01T19:54:21.499Z

Link: CVE-2026-35227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-12T08:16:08.193

Modified: 2026-05-12T08:16:08.193

Link: CVE-2026-35227

cve-icon Redhat

No data.