An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.

Project Subscriptions

Vendors Products
Codesys Subscribe
Codesys Subscribe
Codesys Modbus Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 12 May 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Codesys codesys
Vendors & Products Codesys codesys

Tue, 12 May 2026 07:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
Title Improper resource management in CODESYS Modbus TCP Server
First Time appeared Codesys
Codesys codesys Modbus
Weaknesses CWE-772
CPEs cpe:2.3:a:codesys:codesys_modbus:*:*:*:*:*:*:*:*
Vendors & Products Codesys
Codesys codesys Modbus
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-12T07:14:41.517Z

Reserved: 2026-04-01T19:54:21.499Z

Link: CVE-2026-35227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-12T08:16:08.193

Modified: 2026-05-12T08:16:08.193

Link: CVE-2026-35227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T08:45:11Z

Weaknesses