TCP Connection Exhaustion Vulnerability in CODESYS EtherNet/IP Adapter by CODESYS
CVE-2026-35225
8.7HIGH
What is CVE-2026-35225?
An unauthenticated remote attacker can exploit a vulnerability in the CODESYS EtherNet/IP adapter, overwhelming the TCP connection capacity. This denial-of-service (DoS) attack renders legitimate clients unable to establish new connections, thereby disrupting critical communication within systems utilizing the CODESYS environment. Organizations using the affected products are advised to implement protective measures to safeguard against this type of attack.
Affected Version(s)
CODESYS EtherNetIP 1.0.0.0 < 4.9.0.0
