CVE-2019-14462 is an out-of-bounds read vulnerability in libmodbus versions before 3.0.7 and 3.1.x versions before 3.1.5. The flaw occurs when handling the MODBUS_FC_WRITE_MULTIPLE_COILS function-code case.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive defensive security demonstration for CVE-2019-14462, a heap buffer overflow in libmodbus <= 3.1.2. The project simulates a real-world industrial control system (ICS) environment using Docker containers: a vulnerable PLC (district heating controller) running an unpatched libmodbus, and a gateway container running a QEMU instance of the seL4 microkernel to enforce protocol validation. The exploit code (notably cve_tools/cve_14462_attack.c and related tools) crafts malicious Modbus TCP packets that exploit the length field parsing bug, causing the PLC to crash when accessed directly (port 5020), but are blocked when routed through the seL4 gateway (port 502). The repository includes full build and orchestration scripts, technical documentation, and a local copy of the vulnerable libmodbus source. The exploit is operational, demonstrating both denial-of-service and potential for further memory corruption. The main attack vector is network-based, targeting Modbus TCP endpoints. The repository is intended for educational and defensive research purposes, not for offensive use.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.