← All Advisories

CODESYS EtherNet/IP adapter TCP connection exhaustion blocks legitimate clients without authentication

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-35225

Key Details

CVECVE-2026-35225
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-06-17
Classified asCWE-754 (Improper Check for Unusual or Exceptional Conditions)

What to Know

An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-35225
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-35225