Impact
An out‑of‑bounds read vulnerability exists in the DeleteMonitoredItemsRequest handler of Systerel S2OPC, allowing a local attacker to read memory beyond a buffer when the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse function processes a crafted message. This flaw can leak confidential data present in adjacent memory locations and is classified as a classic out‑of‑bounds read weakness (CWE‑119, CWE‑125). The vulnerability does not provide a remote path and requires local execution, but any local user with sufficient privileges can exploit it to obtain sensitive information.
Affected Systems
The issue affects all Systerel S2OPC installations up to and including version 1.7.3. The vulnerability is present in the state_machine.c component within the client wrapper, and there are currently no publicly available patches from the vendor.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score is currently not available, making it difficult to gauge enumeration probability. Because the attack is local, the potential impact is confined to host‑level data exposure, yet the lack of vendor response and the public availability of the exploit increase the risk to any system that allows local access to the affected binary. The vulnerability is not listed in the CISA KEV catalog, but its local exploitation potential still warrants attention.
OpenCVE Enrichment