Impact
The vulnerability is a heap-based buffer overflow in open62541 1.5.5, triggered when the default history database uses the memory backend during a HistoryRead operation. The description states that malicious parameters can corrupt the heap, and under standard assumptions this could lead to arbitrary code execution at the server host. The actual exploitation scenario is not detailed, so the statement that arbitrary code execution is possible is inferred from the nature of the overflow.
Affected Systems
Installations of open62541 version 1.5.5 that use the default, memory‑backed history database are affected. No other product or vendor versions are mentioned in the advisory.
Risk and Exploitability
The CVSS score of 7.5 signifies high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can remotely trigger the overflow by sending a crafted HistoryRead request over the OPC UA protocol, which is exposed by the server. If the server is internet‑exposed, the risk is higher; internal exposure still poses a threat if an attacker can reach the host.
OpenCVE Enrichment