Executive brief
Eclipse 4diac FORTE is a runtime environment for industrial automation and control systems. A security flaw in its management interface allows an attacker to send a malicious command that corrupts the system's memory. This can lead to system instability, unauthorized data modification, or a complete shutdown of the industrial control processes.
Technical details
A use-after-free vulnerability exists in the CResource::deleteConnection component of Eclipse 4diac FORTE. The flaw is triggered when a specially crafted DELETE connection command is sent to the management interface, resulting in a dangling pointer. Subsequent commands can then access this freed memory. An attacker with access to the adjacent network can exploit this to achieve arbitrary code execution or cause a denial-of-service (DoS) condition. A fix has been proposed in the project's repository via pull request 883.
Affected products
- Eclipse Foundation 4diac FORTE 3.0.0 to 3.1.0
Timeline
- 2026-06-18: advisory: NVD and Eclipse Foundation published the advisory