CVE-2026-35227 Details
Description
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
A resource management vulnerability has been identified in the CODESYS Modbus TCP Server stack, affecting versions prior to 4.6.0.0. This vulnerability allows an unauthenticated remote attacker to exploit a race condition in connection handling, leading to the exhaustion of all available TCP connections. As a result, legitimate clients are prevented from establishing new connections, although existing connections remain unaffected.
Users are advised to update to CODESYS Modbus version 4.6.0.0 or later. For existing CODESYS projects, the local Modbus TCP Server in the device tree must also be updated to the latest version and the CODESYS application downloaded to the PLC. The CODESYS Development System and available CODESYS add-ons can be downloaded via the CODESYS Installer or from the CODESYS Store. Additional update information is available in the CODESYS Update area.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/de/advisories/VDE-2026-042 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-772 | Missing Release of Resource after Effective Lifetime | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |