Impact
A buffer overflow occurs in the Alarm/Conditions wrapper of Systerel S2OPC Toolkit when processing PublishResponse EventNotificationList data. The overflow can corrupt memory and crash the process, resulting in a denial of service. The vulnerability does not expose data or allow code execution; its impact is limited to availability.
Affected Systems
Systerel S2OPC Toolkit version 1.7.3 is affected. The flaw resides in the client/server address space, alarm conditions wrapper, and state machine components that handle PublishResponse messages.
Risk and Exploitability
The attack vector is remote; a malicious actor can craft PublishResponse messages and send them to an OPC UA endpoint that has the Alarm/Conditions feature enabled. The CVSS score of 7.5 indicates high severity. The EPSS score of < 1% shows a low probability of exploitation in the wild, and the vulnerability is not in the CISA KEV list. Nonetheless, because the overflow can be triggered by any network‑connected client, the risk to mission‑critical operations remains significant.
OpenCVE Enrichment