Impact
The vulnerability is a buffer overflow in open62541 v1.5.5 that allows a remote attacker to trigger a denial of service by sending crafted input to the Service_Call function, which validates arguments against runtime‑resolved InputArguments metadata.
Affected Systems
The flaw affects the open62541 OPC UA library, specifically version 1.5.5, used in server implementations that expose Service_Call operations.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity. The EPSS score is below 1%, implying a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote over the network via Service_Call, as inferred from the description.
OpenCVE Enrichment