Impact
The vulnerability concerns a heap‑based buffer overflow in the function UA_Client_readNodeClassAttribute within the open62541 client library. When a local attacker supplies crafted input, the program corrupts heap memory, potentially allowing the attacker to trigger a crash or execute arbitrary code. The exploit is publicly available and has been demonstrated, increasing the risk of exploitation by actors who can interact with the vulnerable binary on the affected system.
Affected Systems
The flaw affects all releases of the open62541 library up to and including version 1.5.5. The vendor lists open62541 as the impacted product; any deployment using this library version is susceptible and should be evaluated for upgrade.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. EPSS data is unavailable, but the vulnerability is not listed in the CISA KEV catalog. Because the attack requires local privilege, the primary risk is to systems where a local attacker can control the input to the library. The publicly disclosed exploit raises the likelihood that an attacker will attempt to use the flaw if the affected environment is reachable.
OpenCVE Enrichment