An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://certvde.com/de/advisories/VDE-2026-042 |
Configurations
No configuration.
History
12 May 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 08:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35227
Mitre link : CVE-2026-35227
CVE.ORG link : CVE-2026-35227
JSON object : View
Products Affected
No product.
CWE
CWE-772
Missing Release of Resource after Effective Lifetime
