Impact
A severe memory corruption vulnerability exists in OpENer 2.3.0. It is caused by an integer underflow that arises when the system processes connected explicit messages through the SendUnitData channel, allowing an attacker to send malformed data that corrupts memory during parsing. Although the description does not guarantee arbitrary code execution, such corruption could enable an attacker to gain code execution or otherwise compromise the system.
Affected Systems
Only OpENer version 2.3.0 that is part of the master branch up to commit 76b95cf is known to be affected. No other vendors or product versions are recorded.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in CISA KEV. No official workaround is provided. Based on the description, the likely attack vector is network-based: an attacker who can reach the target over the network and send crafted SendUnitData messages can trigger the memory corruption.
OpenCVE Enrichment