CVE-2024-34026: Openplcproject OpenPLC v3 Firmware
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
Affected products
- Openplcproject OpenPLC v3 Firmware: version 2024-04-04 only
Published 2024-09-18. Last modified 2026-06-17.