Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libmodbus

First CVE: Jul 31, 2019Active for: 7 yearsTotal CVEs: 9

Libmodbus is a compact, widely embedded C library that implements the Modbus protocol for industrial control and SCADA systems, positioning it across critical infrastructure despite a single-product footprint. Vulnerabilities in the library skew strongly toward critical-severity outcomes and center on memory-safety defects—out-of-bounds reads and writes, heap-based buffer overflows, and classic buffer-overflow conditions—that reflect the challenges of parsing untrusted network input in native code without bounds checking. Defenders should inventory products and appliances that bundle this library, since remediation often depends on downstream vendors, and treat patches as high-priority for internet-exposed or operationally critical systems; live severity and current CVE counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libmodbus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2019
6 years ago
Most Recent CVE
Feb 27, 2025
512 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14463CRITICAL
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.
Jul 31, 20199.132NONO
CVE-2019-14462CRITICAL
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.
Jul 31, 20199.129NONO
CVE-2024-10918CRITICAL
Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request wi
Feb 27, 20259.828NONO
CVE-2023-26793CRITICAL
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.
May 1, 20249.827NONO
CVE-2024-36844HIGH
libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted messa
May 31, 20247.521NONO
CVE-2024-36843HIGH
libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
May 31, 20247.520NONO
CVE-2024-34244HIGH
libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which lead
May 8, 20247.520NONO
CVE-2022-0367HIGH
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
Aug 29, 20227.820NONO
CVE-2024-36845MEDIUM
An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.
May 31, 20244.316NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
44%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libmodbus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libmodbus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libmodbus's Products

View all 3 CNAs →

Top CWEs