Libmodbus is a compact, widely embedded C library that implements the Modbus protocol for industrial control and SCADA systems, positioning it across critical infrastructure despite a single-product footprint. Vulnerabilities in the library skew strongly toward critical-severity outcomes and center on memory-safety defects—out-of-bounds reads and writes, heap-based buffer overflows, and classic buffer-overflow conditions—that reflect the challenges of parsing untrusted network input in native code without bounds checking. Defenders should inventory products and appliances that bundle this library, since remediation often depends on downstream vendors, and treat patches as high-priority for internet-exposed or operationally critical systems; live severity and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libmodbus over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14463CRITICAL An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301. | Jul 31, 2019 | 9.1 | 32 | NO | NO |
CVE-2019-14462CRITICAL An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302. | Jul 31, 2019 | 9.1 | 29 | NO | NO |
CVE-2024-10918CRITICAL Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request wi | Feb 27, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-26793CRITICAL libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. | May 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-36844HIGH libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted messa | May 31, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-36843HIGH libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. | May 31, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-34244HIGH libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which lead | May 8, 2024 | 7.5 | 20 | NO | NO |
CVE-2022-0367HIGH A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. | Aug 29, 2022 | 7.8 | 20 | NO | NO |
CVE-2024-36845MEDIUM An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | May 31, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libmodbus.
Media articles that mention a CVE ID that affects a product developed by Libmodbus — matched by CVE ID, not by vendor name.