Denial of Service Vulnerability in OpenPLC ModbusTCP Server
CVE-2025-53476

5.3MEDIUM

Key Information:

Vendor

Openplc

Vendor
CVE Published:
7 October 2025

What is CVE-2025-53476?

A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC v3. A specially crafted sequence of TCP network connections can disrupt server processing of subsequent Modbus requests. This can be exploited by an attacker to create multiple TCP connections, thereby rendering the server unresponsive to further Modbus interactions.

Affected Version(s)

OpenPLC_v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by a member of Cisco Talos.
.
CVE-2025-53476 : Denial of Service Vulnerability in OpenPLC ModbusTCP Server