LEARGAS OT EXPLOIT Modbus FC04 read-input-registers quantity beyond spec (>125) - possible MicroLogix 1400 CVE-2021-22659
Sourceleargas/public
Filemodbus.rules
CreatedAugust 10, 2026
UpdatedAugust 10, 2026
Classificationattempted-dos
alert tcp any any -> $HOME_NET 502 (msg:"LEARGAS OT EXPLOIT Modbus FC04 read-input-registers quantity beyond spec (>125) - possible MicroLogix 1400 CVE-2021-22659"; flow:to_server,established ; content:"|00 00|"; offset:2; depth:2; content:"|04|"; offset:7; depth:1; byte_test:2,>,125,2,relative,big ; classtype:attempted-dos; reference:cve,2021-22659 ; reference:url,www.cisa.gov/news-events/ics-advisories/icsa-21-033-01 ; metadata:affected_product Rockwell_MicroLogix_1400, tag OT, tag Modbus, cve CVE_2021_22659, deployment Internal, signature_severity Major, created_at 2026_08_10; target:dest_ip; sid:42122661; rev:1;)
References
Metadata
affected productRockwell_MicroLogix_1400
tagModbus
deploymentInternal
signature severityMajor
created at2026_08_10
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!