Impact
A buffer overflow exists in the Discovery/LDS handling of the open62541 library, allowing an attacker that can reach the server over the network to cause a crash and deny service to all clients accessing the server. The flaw results from insufficient bounds checking when parsing discovery messages, leading to memory corruption and application termination. This disruption can affect any system relying on continuous availability of an OPC UA server for control or monitoring functions.
Affected Systems
The vulnerability is present in the open62541 open‑source OPC UA library, specifically version 1.5.5. Systems that compile and run this version of the library in a server configuration, especially those that expose the discovery endpoints to external networks, are affected. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, whereas the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is triggered via the server’s discovery protocol, the likely attack vector is remote network traffic, such as UDP or mDNS messages directed at the discovery interfaces. An attacker would need to send a crafted message to the vulnerable server; if successful, the server will crash, resulting in a denial of service for all clients. No authentication or privilege escalation is required, making the risk immediate for exposed servers.
OpenCVE Enrichment