Impact
The flaw resides in the TSnap7Peer::NegotiatePDULength routine of davenardella snap7, where an improperly validated PDULength argument leads to an out-of-bounds write. This memory corruption can corrupt internal structures or trigger unintended execution paths, potentially leading to denial of service or other unintended behavior.
Affected Systems
davenardella Snap7, versions up to 1.4.3, accessed remotely via the default Snap7 interface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access to the Snap7 service, inferred from the description that the attack can be executed remotely. Once an attacker sends a specially crafted PDULength value over the Snap7 session, the out-of-bounds write can corrupt memory and may lead to a process crash or other unintended behavior.
OpenCVE Enrichment