CVE-2026-35225 Details
Description
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.
A vulnerability exists in the CODESYS EtherNet/IP adapter stack, affecting versions prior to 4.9.0.0. Under certain non-standard operating conditions, the adapter fails to properly manage TCP connection timeouts. This oversight allows an unauthenticated remote attacker to exhaust all available TCP connections, blocking legitimate clients from establishing new connections. The issue arises only in CODESYS projects that include an EtherNet/IP adapter configuration.
Users are advised to update CODESYS EtherNetIP to version 4.9.0.0. The CODESYS Development System and its add-ons can be downloaded via the CODESYS Installer or from the CODESYS Store. Additional update information is available in the CODESYS Update area on the CODESYS website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | New CVE Received | [email protected] |