← Vulnerability feed

Vulnerability record · CVE-2018-20818 · published 22 April 2019

CVE-2018-20818: Openplcproject openplc v2 firmware memory buffer overflow vulnerability

Openplcproject · Openplc V2 Firmware

A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact.

9.8 CVSS 3.0 Critical EPSS 1.5% · top 26.2% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 7.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://arxiv.org/pdf/1809.07477 Third Party Advisory
https://arxiv.org/pdf/1809.07477 Third Party Advisory

Track CVE-2018-20818 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34026Openplcproject openplc v3 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b454…EPSS 2.4%9.2CVE-2026-35556Openplcproject openplc v3 firmware vulnerabilityOpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive…EPSS 0.40%9.2CVE-2026-28205Openplcproject openplc v3 firmware insecure default initialization vulnerabilityOpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th…EPSS 0.67%8.8CVE-2021-31630Openplcproject openplc v3 firmware code injection vulnerabilityCommand Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/har…EPSS 27%8.7CVE-2026-35063Openplcproject openplc v3 firmware missing authorization vulnerabilityOpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other…EPSS 0.43%7.5CVE-2024-36981Openplcproject openplc v3 firmware out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298…EPSS 1.0%7.5CVE-2024-39589Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%7.5CVE-2024-39590Openplcproject openplc v3 firmware vulnerabilityMultiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2018-20818), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.