天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-102511 Apache PLC4X PLC4Go ADS 发现源验证不当漏洞

影响攻击者可重定向连接至任意主机并窃取路由凭据

AI 研判

Apache PLC4X 的 Go 实现(PLC4Go)在 ADS 设备发现过程中未正确校验通信来源,发现结果中的连接地址取自响应体声明的 AmsNetId,而非数据报的真实源地址。攻击者只需发送一个伪造的 UDP 发现响应,即可向设备清单中插入指向任意主机的条目。此外,PLC4Go 与 PLC4J 的发现监听器均可被单个畸形数据报中断。

影响范围

Apache PLC4X

受影响组件为 Apache PLC4X 的 Go 实现(PLC4Go)ADS 发现功能,以及 PLC4J 的 ADS、EtherNet/IP、Modbus 发现器。具体受影响版本范围暂无公开信息。

漏洞详情

漏洞属于通信通道来源验证不当(CWE-940)。ADS 发现响应中的连接地址直接采用报文内声明的 AmsNetId,未与 UDP 数据报的实际源 IP 比对,因此攻击者可伪造响应,使应用后续连接至攻击者指定主机,并可能泄露配置的 ADS 路由凭据。同时,畸形数据报可触发 PLC4Go 的 panic 或 PLC4J 的未处理异常,导致发现监听器停止,PLC4J Modbus 发现器还可被诱导无限循环占用 CPU。

利用条件与风险

利用前提是攻击者能向发现主机发送 UDP 数据报,通常需处于同一网络或可路由至该主机。实战中可导致连接劫持、凭据泄露及发现服务拒绝服务,风险较高。

修复建议

建议关注 Apache PLC4X 官方发布的安全公告并升级至修复版本;在修复前,可限制发现端口的网络访问、避免在不可信网络中使用 ADS 发现功能,或改用显式配置的设备地址。具体修复版本暂无公开信息。

原始情报

Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result’s connection
address was derived from the AmsNetId claimed in the response body rather than from the datagram’s actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices
will open its ADS session, including any configured route credentials, to that host.

Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram:
– In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.
– In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.
– The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.

Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.

This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.

Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram’s source address and logs a warning when the claimed AmsNetId disagrees with it.