Impact
An out‑of‑bounds read exists in the unconnected explicit messaging path of OpENer (commit 76b95cf). The flaw is triggered by a remote actor feeding crafted messages, causing the software to read beyond allocated memory and trigger a crash. The resulting denial of service removes the affected service from operation without any data loss or credential compromise.
Affected Systems
The vulnerability is present in OpENer version 2.3.0 as described by the listed commit. No CNA vendor product names are supplied, but the affected system is the OpENer open‑source stack used for industrial Ethernet/IP communication.
Risk and Exploitability
The CVSS score of 7.5 reflects a high impact for denial of service. EPSS information is unavailable, and the issue is not listed in the CISA KEV catalog, which suggests no currently known active exploitation. However, the remote attack vector and the severe availability impact make addressing this flaw a priority, especially for systems exposed to untrusted networks.
OpenCVE Enrichment