Impact
A buffer overflow exists in Systerel S2OPC version 1.7.3 that is triggered by the AddNodes service via the files address_space_bs.c, sopc_node_mgt_helper_internal.c, and the toolkit test server. The overflow allows an attacker to send a crafted request over the network that corrupts memory and causes the application to crash, leading to a denial of service. The vulnerability is a classic out‑of‑bounds write that could be exploited by an unauthenticated remote actor because the service is exposed on the public interface of the S2OPC server.
Affected Systems
Systerel S2OPC Toolkit 1.7.3, the only version specified by the notifier. No additional vendor information is available, but any deployment using this toolkit version without patch is vulnerable. The affected components are the internal node management helpers and address space service files listed in the source.
Risk and Exploitability
The CVSS score is not disclosed, but the lack of an available EPSS score and the absence of KEV listing suggest that the vulnerability is known but not yet widely exploited. However, because the flaw is remote and leads to a complete service crash, the impact is high. The attack likely requires the attacker to send a crafted AddNodes request over the network, which can be performed by anyone who can reach the S2OPC endpoint.
OpenCVE Enrichment