Description
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based out‑of‑bounds write occurs in the server‑side EventFilter handling of CreateMonitoredItems in S2OPC 1.7.3. The flaw allows an attacker that can send a crafted request to the server to overwrite memory beyond the intended buffer, leading to arbitrary code execution on the host that runs the S2OPC server. The impact is a complete compromise of confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerable component is the S2OPC server version 1.7.3. No other vendor or product versions are listed, and the product name is not specified beyond the S2OPC library. Systems running this exact library version should consider themselves impacted.

Risk and Exploitability

The vulnerability is exploitable remotely over the network via a CreateMonitoredItems request containing a malformed EventFilter. No authentication or privileged state is required, so any party that can reach the server may trigger the exploit. Although an EPSS score is not available and the issue is not listed in CISA KEV, the nature of the flaw (an out‑of‑bounds write that grants code execution) typically indicates a high severity. The likelihood of exploitation is considered non‑negligible for exposed services. The attack vector is inferred to be remote due to the network‑based service involved.

Generated by OpenCVE AI on August 18, 2026 at 00:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the S2OPC library to a version that contains the fix (e.g., 1.7.4 or later if available).
  • Restrict network exposure of the S2OPC server by placing it behind a firewall or VPN so that only trusted clients can send CreateMonitoredItems requests.
  • Monitor logs for unexpected CreateMonitoredItems traffic and alert on anomalous EventFilter payloads.
  • When the fix is not available, consider disabling the EventFilter feature or reconfiguring the server to reject EventFilter requests from untrusted clients.

Generated by OpenCVE AI on August 18, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Heap Out‑of‑Bounds Write in S2OPC Server EventFilter Enables Remote Code Execution
Weaknesses CWE-787

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Systerel
Systerel s2opc
Vendors & Products Systerel
Systerel s2opc

Mon, 17 Aug 2026 22:00:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T21:51:09.964Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:25.790

Modified: 2026-08-17T22:17:25.790

Link: CVE-2026-67868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:15:03Z

Weaknesses