Description
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow exists in Systerel S2OPC version 1.7.3 that is triggered by the AddNodes service via the files address_space_bs.c, sopc_node_mgt_helper_internal.c, and the toolkit test server. The overflow allows an attacker to send a crafted request over the network that corrupts memory and causes the application to crash, leading to a denial of service. The vulnerability is a classic out‑of‑bounds write that could be exploited by an unauthenticated remote actor because the service is exposed on the public interface of the S2OPC server.

Affected Systems

Systerel S2OPC Toolkit 1.7.3, the only version specified by the notifier. No additional vendor information is available, but any deployment using this toolkit version without patch is vulnerable. The affected components are the internal node management helpers and address space service files listed in the source.

Risk and Exploitability

The CVSS score is not disclosed, but the lack of an available EPSS score and the absence of KEV listing suggest that the vulnerability is known but not yet widely exploited. However, because the flaw is remote and leads to a complete service crash, the impact is high. The attack likely requires the attacker to send a crafted AddNodes request over the network, which can be performed by anyone who can reach the S2OPC endpoint.

Generated by OpenCVE AI on August 6, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of the S2OPC toolkit once it is released.
  • If a patch is not yet available, modify the buffer handling code in address_space_bs.c and sopc_node_mgt_helper_internal.c to enforce bounds checks before memory operations.
  • Disable the AddNodes service in the S2OPC configuration to eliminate the attack surface until a patch is applied.
  • Restrict network access to the S2OPC server so that only trusted hosts can reach the AddNodes endpoint, using firewall or VLAN segmentation.

Generated by OpenCVE AI on August 6, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in Systerel S2OPC 1.7.3
First Time appeared Systerel
Systerel s2opc
Weaknesses CWE-787
Vendors & Products Systerel
Systerel s2opc

Wed, 05 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-05T23:12:07.704Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67871

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T00:30:03Z

Weaknesses