{"id":"CVE-2024-10918","title":"Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an\nunexpected length.","summary":"Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an\nunexpected length.","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-121","CWE-787"],"vendor":"libmodbus","product":"libmodbus","affected":["libmodbus = 3.1.10"],"published":"2025-02-27","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-10918","references":[{"url":"https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-10918","label":"prodsec@nozominetworks.com"},{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00010.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2026/08/msg00003.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00562,"epssPercentile":0.44387,"ingestedAt":"2026-08-01T20:14:18.536Z","slug":"CVE-2024-10918","body":"## Overview\n\nStack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an\nunexpected length.\n\n## Affected\n\n- `libmodbus = 3.1.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":26.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}