Impact
S2OPC 1.7.3 implements the RepublishResponse handling routine with an out‑of‑bounds read, a flaw that allows a remote party to trigger a denial of service. The vulnerability is a classic memory read error, classified under CWE‑125, which can cause an application crash or loss of service when a malformed or unexpected RepublishResponse is processed.
Affected Systems
The affected product is the S2OPC Toolkit, specifically version 1.7.3. All libraries or executables built from S2OPC 1.7.3 that process RepublishResponse messages are potentially impacted. No additional vendor or product versions are listed, so the scope is limited to this version but could affect any deployments using it.
Risk and Exploitability
The vulnerability can be exploited by a remote attacker who can send crafted RepublishResponse messages to a S2OPC 1.7.3 instance. The attack does not require local privileges and can be performed over the network. Because the flaw leads to a denial of service, the impact is primarily availability disruption. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the potential for widespread deployment of the affected library could make it a high-value target for disruptors. Immediate patching or mitigation is advised because the risk to availability is significant.
OpenCVE Enrichment