CVE-2019-14462

CRITICAL LAB

libmodbus <3.0.7, <3.1.5 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-14462. PoCs published by spanwich.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2019-14462, a heap buffer overflow in libmodbus 3.1.2, along with a detailed technical analysis and a defensive research framework comparing seL4 and Snort architectures. The PoC demonstrates the vulnerability by exploiting malformed MBAP header length fields.

Description

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.

Exploits (1)

nomisec WORKING POC
by spanwich · poc
https://github.com/spanwich/sel4-ics-gateway-demo

This repository contains functional exploit code for CVE-2019-14462, a heap buffer overflow in libmodbus 3.1.2, along with a detailed technical analysis and a defensive research framework comparing seL4 and Snort architectures. The PoC demonstrates the vulnerability by exploiting malformed MBAP header length fields.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: libmodbus ≤ 3.1.2
No auth needed
Prerequisites: Network access to a vulnerable Modbus server · Ability to send crafted Modbus packets
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://libmodbus.org/2019/stable-and-development-releases/
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/11/msg00020.html

Scores

CVSS v3 9.1
EPSS 0.0198
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull frosty-goop-poc:asan
docker pull frosty-goop-poc:normal

Details

CWE
CWE-125
Status published
Products (4)
debian/debian_linux 9.0
fedoraproject/fedora 29
fedoraproject/fedora 30
libmodbus/libmodbus < 3.0.7
Published Jul 31, 2019
Tracked Since Feb 18, 2026