Impact
The flaw resides in the TS7Worker::PerformFunctionRead routine within the core snap7 server component, where a ReadVar request is processed without proper bounds checking. An attacker with local‑network access can send a malicious request that triggers an out‑of‑bounds write, potentially corrupting memory and causing unpredictable behavior. This weakness corresponds to CWE‑119 and CWE‑787, and while an exploit exists that can cause memory corruption, a confirmed code‑execution outcome has not yet been formally published by the vendor.
Affected Systems
All installations of davenardella snap7 version 1.4.3 and earlier are affected. The vulnerability lies in the core s7_server code, so any deployment that exposes the snap7 interface over a local or untrusted network—regardless of operating system—is within scope.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of widespread exploitation, yet a publicly available proof‑of‑concept exploit has already been released, demonstrating that an attacker with local network access can exploit this flaw. The vulnerability is not listed in the CISA KEV catalog, but the existence of a functional exploit necessitates prompt remediation and network segmentation.
OpenCVE Enrichment