CVE Database
/

CVE-2026-4436

Back to search

CVE-2026-4436

Published: Apr 9, 2026

Modified: Apr 14, 2026

PUBLISHED

CVSS v3.1

8.6

HIGH

Description

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

VendorProductVersions

GPL Odorizers

GPL750 (XL4)

affected
v1.0 - < v6.0

GPL Odorizers

GPL750 (XL4 Prime)

affected
v4.0 - < v6.0

GPL Odorizers

GPL Odorizers GPL750 (XL7)

affected
v13.0 - < v20.0

GPL Odorizers

GPL Odorizers GPL750 (XL7 Prime)

affected
v18.4 - < v20.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now