Controller halt via oversized Modbus/TCP request
Published Oct 9, 2023 · Updated Aug 2, 2024
Denial of service in the XINJE XD5E-30R-E 3.5.3b Modbus handler allows remote attackers to stop the controller via Modbus/TCP. The handler accepts at least 0x58C bytes, turns on the ERR indicator, and stops device operation instead of safely rejecting the oversized data. The interface listens on TCP port 502 by default and requires no authentication, but public evidence does not establish whether recovery requires a reboot or other intervention.
Summary
What happened
Denial of service in the XINJE XD5E-30R-E 3.5.3b Modbus handler allows remote attackers to stop the controller via Modbus/TCP. The handler accepts at least 0x58C bytes, turns on the ERR indicator, and stops device operation instead of safely rejecting the oversized data. The interface listens on TCP port 502 by default and requires no authentication, but public evidence does not establish whether recovery requires a reboot or other intervention.
The record
- CVE
- CVE-2023-5462
- Published
- Oct 9, 2023
- Updated
- Aug 2, 2024
- Vendor
- Wuxi Xinje Electric Co., Ltd.
- Product
- XD5E-30R-E Firmware
- Classifications
- CWE-404, T0814
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Oct 9, 2023CVE publishedPublication date reported by the CVE source.
- Aug 2, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.5.3b
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- XD5E-30R-E oversized Modbus/TCP request demonstrationfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo