Impact
A buffer overflow occurs in the Alarm/Conditions wrapper of Systerel S2OPC Toolkit when processing PublishResponse EventNotificationList data, allowing a remote attacker to corrupt memory and cause the process to crash. This results in a denial of service against the affected system, compromising availability without directly exposing data or executing arbitrary code.
Affected Systems
Systerel S2OPC Toolkit, version 1.7.3 is affected. The vulnerability exists in the client/server address space, alarm conditions wrapper, and state machine components handling publish responses.
Risk and Exploitability
The attack vector is remote, requiring the attacker to send crafted PublishResponse messages to a S2OPC instance that advertises the Alarm/Conditions feature. Although EPSS data is not available and the vulnerability is not in the CISA KEV list, the buffer overflow can be triggered over the network by any attacker with access to the OPC UA endpoint, making the risk significant. The denial of service outcome can disrupt mission‑critical operations that rely on S2OPC for real‑time data exchange.
OpenCVE Enrichment