Description
S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

S2OPC 1.7.3 implements the RepublishResponse handling routine with an out‑of‑bounds read, a flaw that allows a remote party to trigger a denial of service. The vulnerability is a classic memory read error, classified under CWE‑125, which can cause an application crash or loss of service when a malformed or unexpected RepublishResponse is processed.

Affected Systems

The affected product is the S2OPC Toolkit, specifically version 1.7.3. All libraries or executables built from S2OPC 1.7.3 that process RepublishResponse messages are potentially impacted. No additional vendor or product versions are listed, so the scope is limited to this version but could affect any deployments using it.

Risk and Exploitability

The vulnerability can be exploited by a remote attacker who can send crafted RepublishResponse messages to a S2OPC 1.7.3 instance. The attack does not require local privileges and can be performed over the network. Because the flaw leads to a denial of service, the impact is primarily availability disruption. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the potential for widespread deployment of the affected library could make it a high-value target for disruptors. Immediate patching or mitigation is advised because the risk to availability is significant.

Generated by OpenCVE AI on August 5, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor supplied patch for S2OPC 1.7.3 or upgrade to a later release that contains the fix.
  • If a patch is not yet available, isolate the affected service by restricting network access to the S2OPC instance or by disabling the Republish functionality until a fix can be applied.
  • Deploy an OPC UA traffic filter or intrusion detection rule to block malformed RepublishResponse messages or to log potential attempts for early detection.

Generated by OpenCVE AI on August 5, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in S2OPC 1.7.3 RepublishResponse Causes DoS
Weaknesses CWE-125

Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Systerel
Systerel s2opc
Vendors & Products Systerel
Systerel s2opc

Wed, 05 Aug 2026 22:15:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-05T22:02:30.787Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67865

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T00:00:10Z

Weaknesses