Description
A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted Common Packet Format (CPF) packet.
Published: 2026-06-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer overflow in the Get_Attribute_List function of the EIPStackGroup OpENer network stack. When a specially crafted Common Packet Format packet is processed, the internal buffer is overwritten, causing the function to terminate unexpectedly. This results in the application process failing and the network service becoming unavailable. The flaw is classified as CWE-284, an improper access control weakness, leading to a denial of service.

Affected Systems

The flaw resides in the OpENer source code at commit 76b95c. Any deployment that uses this commit or a derivative of the same source code may be affected. No vendor name or version range is specified, so any system incorporating the affected code at or after that revision could be exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high impact. The EPSS score of < 1% shows that the probability of exploitation is very low at this time, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, based on the fact that the overflow is triggered by a network packet. An attacker would need the ability to send a crafted CPF packet to the vulnerable function; if successful, the service would crash, causing a denial of service.

Generated by OpenCVE AI on June 30, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a patch or upgrade to a later OpENer revision that removes the Get_Attribute_List buffer overflow.
  • If an update cannot be performed immediately, block or filter incoming Common Packet Format packets at the network perimeter to prevent the overflow trigger.
  • Continuously monitor the application logs and system resource usage for signs of crashes or abnormal CPU spikes that may indicate attempted exploitation.

Generated by OpenCVE AI on June 30, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Title OpENer Network Stack Buffer Overflow Enables Denial of Service via CPF Packet

Tue, 30 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Get_Attribute_List Buffer Overflow Enables Denial of Service
Weaknesses CWE-120
CWE-787

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Eipstackgroup
Eipstackgroup opener
Vendors & Products Eipstackgroup
Eipstackgroup opener

Tue, 30 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
Title Get_Attribute_List Buffer Overflow Enables Denial of Service
Weaknesses CWE-120
CWE-787

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted Common Packet Format (CPF) packet.
References

Subscriptions

Eipstackgroup Opener
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-30T13:17:51.840Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51221

cve-icon Vulnrichment

Updated: 2026-06-30T13:16:15.264Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T19:30:17Z

Weaknesses