Impact
A buffer overflow exists in the Systerel S2OPC Toolkit version 1.7.3. The flaw is triggered by the AddNodes service and is implemented in the files address_space_bs.c and sopc_node_mgt_helper_internal.c. An attacker who can send a specially crafted request can overwrite memory and cause the S2OPC server to crash, resulting in a denial of service. This vulnerability is a classic out‑of‑bounds write identified as CWE‑120.
Affected Systems
Systerel S2OPC Toolkit 1.7.3 is the only version explicitly listed as vulnerable. Any deployment that uses this version without applying a fix is at risk. No additional vendors or product variants are identified in the CVE record.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑high severity level, while the EPSS score of < 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. The AddNodes service is a network‑exposed endpoint, so the likely attack vector is a remote attacker sending a crafted request over the network. If exploited, the impact would be limited to the affected instance, causing it to become unavailable.
OpenCVE Enrichment