Impact
Open62541 version 1.5.5 contains an incomplete validation flaw in the server‑side AddReferences implementation for non‑local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non‑zero targetNodeId.serverIndex, causing an internal pointer to remain NULL while the server continues processing. This null pointer dereference results in the server process crashing or terminating unexpectedly, leading to a denial of service. The weakness maps to CWE‑476.
Affected Systems
The vulnerable product is the open62541 open‑source OPC UA library, version 1.5.5. No other vendors or product variants are listed in the advisory.
Risk and Exploitability
The flaw is exploitable remotely over the network. Although the EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, the presence of a NULL pointer dereference combined with missing input validation presents a high potential for service disruption. The CVSS score of 9.8 indicates a high severity. Current risk is moderate to high until an official patch or mitigation is applied.
OpenCVE Enrichment