LEARGAS OT EXPLOIT Modbus FC04 read-input-registers quantity beyond spec (>125) - possible MicroLogix 1400 CVE-2021-22659

SID: 42122661Rev: 1Enabled6 views
Filemodbus.rules
CreatedAugust 10, 2026
UpdatedAugust 10, 2026
Classificationattempted-dos
alert tcp any any -> $HOME_NET 502 (msg:"LEARGAS OT EXPLOIT Modbus FC04 read-input-registers quantity beyond spec (>125) - possible MicroLogix 1400 CVE-2021-22659"; flow:to_server,established; content:"|00 00|"; offset:2; depth:2; content:"|04|"; offset:7; depth:1; byte_test:2,>,125,2,relative,big; classtype:attempted-dos; reference:cve,2021-22659; reference:url,www.cisa.gov/news-events/ics-advisories/icsa-21-033-01; metadata:affected_product Rockwell_MicroLogix_1400, tag OT, tag Modbus, cve CVE_2021_22659, deployment Internal, signature_severity Major, created_at 2026_08_10; target:dest_ip; sid:42122661; rev:1;)

Metadata

affected productRockwell_MicroLogix_1400
tagModbus
deploymentInternal
signature severityMajor
created at2026_08_10

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!