天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-102510 Apache PLC4X PLC4Go 拒绝服务漏洞

影响攻击者可导致客户端应用崩溃或内存耗尽,造成拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Apache PLC4X 的 Go 语言实现(PLC4Go)存在整数溢出、数组索引校验不当、无限制递归及超大内存分配等多个缺陷。恶意设备或能注入网络流量的攻击者可利用这些缺陷使客户端应用崩溃或内存耗尽,导致拒绝服务。

影响范围

Apache PLC4X PLC4Go

受影响组件为 Apache PLC4X 的 Go 实现(PLC4Go),其中生成解析器的预分配数组问题涉及 0.13.0 至 0.13.1 版本;其他缺陷的具体版本范围暂无公开信息。

漏洞详情

漏洞成因包括:生成的解析器按报文声明的元素数量预分配数组、传输读取辅助函数按报文声明大小无上限分配缓冲区、ADS 与 KNXnet/IP 响应处理未校验长度即索引数据导致 panic、ADS 与 EIP 帧长度处理接受或回绕为零长度破坏消息分帧、递归协议类型解析无嵌套深度限制,以及生成序列化器使用 16 位整数进行长度与位置运算,转发超过 8KB 的载荷时长度字段回绕。攻击者可通过构造恶意报文触发上述缺陷。

利用条件与风险

利用前提是攻击者能控制或注入发往客户端的网络流量(如恶意设备或中间人)。实战中可远程造成客户端崩溃或内存耗尽,形成拒绝服务,无需认证。

修复建议

建议升级到修复该漏洞的 Apache PLC4X 版本,具体修复版本请参考 Apache 官方安全公告;临时缓解措施包括对来自设备的报文长度与嵌套深度进行限制、隔离不可信网络设备,暂无其他公开信息。

原始情报

Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,
causing a denial of service.

The individual defects are:
– Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).
– Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.
– ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.
– ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.
– Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .

Additionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as
additional, independent protocol messages.

This issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.

Users are recommended to upgrade to version 1.0.0, which fixes the issue.