CVE-2021-43083

HIGH

Apache PLC4X - PLC4C <0.9.1 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/12/20/2

Scores

CVSS v3 8.8
EPSS 0.0207
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-191
Status published
Products (1)
apache/plc4x < 0.9.1
Published Dec 19, 2021
Tracked Since Feb 18, 2026