nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows…
TuranSec·CWE-193·Published 2026-06-14
nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255.
nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255.
nanoMODBUS hasta la v1.23.0 contiene un desbordamiento de búfer por un byte en la función recv_msg_header() del servidor Modbus/TCP que permite a atacantes remotos no autenticados escribir un byte controlado por el atacante más allá del final del búfer de recepción de 260 bytes enviando una trama MBAP manipulada cuyo campo Length está configurado en 255. El desbordamiento corrompe el campo adyacente buffer-index de la estructura de estado de nanoMODBUS, lo que resulta en denegación de servicio a través de accesos a memoria no válidos y, en objetivos bare-metal y RTOS sin protección de memoria, revelación de información de un byte y escrituras a direcciones de registro no intencionadas en la ruta del gestor de Write Multiple Registers (FC16).
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | cve.org | 9.0 | — | — | AV:N/AC:L/Au:N/C:P/I:P/A:C |
| 2.0 | Secondary | NVD | 9.0 | 10.0 | 8.5 | AV:N/AC:L/Au:N/C:P/I:P/A:C |
| 3.1 | Primary | cve.org | 8.6 | — | — | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| 3.1 | Secondary | NVD | 8.6 | 3.9 | 4.7 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| 4.0 | Primary | cve.org | 7.8 | — | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y |
| 4.0 | Secondary | ENISA EUVD | 7.8 | — | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y |
| 4.0 | Secondary | NVD | 7.8 | — | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X |