Impact
Open62541 1.5.5 contains a heap‑based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend. The overflow occurs while handling a HistoryRead request, and an attacker that can supply malicious parameters can corrupt the heap and potentially execute arbitrary code. The description indicates a classic out‑of‑bounds write that could be leveraged to compromise the host running the OPC UA server library.
Affected Systems
Any installation of open62541 version 1.5.5 that uses the default history database with the memory backend is affected. The vulnerability is tied to the memory‑backend implementation of the history database; no other product or vendor versions are mentioned.
Risk and Exploitability
The buffer overflow can lead to arbitrary code execution if an attacker can send a crafted HistoryRead request to the exposed OPC UA server. While the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the nature of the flaw and the potential for remote exploitation via the OPC UA protocol suggest a high risk if the server is internet‑exposed. Internal or restricted networks reduce the immediate threat but do not eliminate the risk of an exploitation attempt if the server is reachable within the local environment.
OpenCVE Enrichment