CRITICAL🇵🇱 Wersja polska

CVE-2026-35556

CVSS 9.2v4.0pub. 2026-04-09upd. 2026-04-16

OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

🤖 AI Analysis
How it works

According to CWE-256, the application stores passwords in an unsecured manner — in plaintext — instead of using secure mechanisms such as salted hashing. An attacker who gains access to the file system, database, or device memory can directly read authentication credentials without needing to crack them. The attack vector is network-based and does not require prior authentication or user interaction, although specific environmental conditions may be necessary for exploitation (AT:P).

Impact

An attacker can recover user authentication credentials (login and password) of the system and gain unauthorized access to sensitive functions and information managed by the OpenPLC V3 controller. Credential compromise in an industrial environment can lead to takeover of automation processes.

Mitigation & patch

Apply patches available from the manufacturer according to references. Additionally, it is recommended to: isolate OT/ICS networks from corporate networks and the Internet, restrict access to the OpenPLC management interface to trusted hosts only, and monitor attempts of unauthorized access. Detailed recommendations are contained in the CISA advisory at https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-10.

Who is affected

OpenPLC V3 Firmware and OpenPLC V3 (products: Openplcproject Openplc V3 Firmware, Openplcproject Openplc V3); specific versions indicated in manufacturer references and CISA ICS-CERT advisory ICSA-25-345-10.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openplcproject Openplc V3

    HW
    Openplcproject
    all versions
  • Openplcproject Openplc V3 Firmware

    OS
    Openplcproject
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-28205CRITICAL9.2PL ✓same product

OpenPLC V3 — pominięcie uwierzytelnienia przez niezabezpieczoną domyślną inicjalizację

CVE-2024-34026CRITICAL9.0PL ✓same product

Stack-based buffer overflow w OpenPLC V3 — RCE przez EtherNet/IP

CVE-2018-20818CRITICAL9.8PL ✓same product

Buffer overflow w OpenPLC V2/V3 — funkcja mapUnusedIO() w modbus.cpp

CVE-2026-35063HIGH8.7same product

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated u...

CVE-2024-36981HIGH7.5same product

An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of Ope...