Description
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.
Published: 2026-07-13
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read (CWE‑125) in the Connection Manager component of OpENer when it processes malformed ForwardOpen or LargeForwardOpen packets. A malicious actor can send a valid ENIP outer frame with a CIP ForwardOpen packet that does not contain enough data. The parser will read past the end of the supplied packet, potentially exposing data stored elsewhere in memory. The description does not indicate that the flaw causes crashes or memory corruption.

Affected Systems

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) is the only product listed as vulnerable. No other vendors or versions are reported to be affected.

Risk and Exploitability

An adversary can trigger the vulnerability remotely over the network without authentication. The EPSS score is reported as less than 1%, and the flaw is not included in the CISA KEV catalog, making the precise likelihood of exploitation unclear. With a CVSS score of 9.1, the severity is high, underscoring the importance of mitigating this vulnerability promptly. The remote trigger and lack of authentication gate mean that hosts exposed to untrusted networks face a moderate to high risk. If the server is behind a firewall or otherwise isolated, the threat is mitigated, but any exposed instance can be abused to read sensitive data from memory.

Generated by OpenCVE AI on August 3, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpENer to a version that includes the fix for the out‑of‑bounds read in the Connection Manager
  • Configure firewall or network ACLs to allow ENIP traffic only from trusted hosts
  • Implement packet inspection or drop malformed CIP ForwardOpen/LargeForwardOpen requests before they reach the Connection Manager

Generated by OpenCVE AI on August 3, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 15 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in OpENer ForwardOpen Parser OpENer: OpENer: Out-of-bounds read via malformed ForwardOpen requests
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in OpENer ForwardOpen Parser
Weaknesses CWE-20

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Eipstackgroup
Eipstackgroup opener
Vendors & Products Eipstackgroup
Eipstackgroup opener

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.
References

Subscriptions

Eipstackgroup Opener
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-14T13:16:42.741Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51537

cve-icon Vulnrichment

Updated: 2026-07-14T13:16:10.645Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-13T00:00:00Z

Links: CVE-2026-51537 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:00:13Z

Weaknesses