Impact
A buffer overflow exists in the Systerel S2OPC client wrapper implementation of DeleteMonitoredItems, specifically in the functions LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems. When a crafted DeleteMonitoredItems response is received, the overflow corrupts memory and allows a remote attacker to crash the process, resulting in a denial of service. This vulnerability is a classic buffer overflow issue where input validation is insufficient, matching CWE-120/122 vulnerability classes.
Affected Systems
Systerel S2OPC version 1.7.3 is affected. No other product or version information is provided.
Risk and Exploitability
The vulnerability permits remote exploitation without authentication. No CVSS score is available, but the absence of an EPSS rating and lack of KEV listing does not diminish the risk; attackers can easily trigger the crash by sending a malicious DeleteMonitoredItems response. Any system running the vulnerable version could be taken offline, disrupting availability of OPC UA services.
OpenCVE Enrichment