Description
OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Update
AI Analysis

Impact

An out‑of‑bounds read exists in the unconnected explicit messaging path of OpENer (commit 76b95cf). The flaw is triggered by a remote actor feeding crafted messages, causing the software to read beyond allocated memory and trigger a crash. The resulting denial of service removes the affected service from operation without any data loss or credential compromise.

Affected Systems

The vulnerability is present in OpENer version 2.3.0 as described by the listed commit. No CNA vendor product names are supplied, but the affected system is the OpENer open‑source stack used for industrial Ethernet/IP communication.

Risk and Exploitability

The CVSS score of 7.5 reflects a high impact for denial of service. EPSS information is unavailable, and the issue is not listed in the CISA KEV catalog, which suggests no currently known active exploitation. However, the remote attack vector and the severe availability impact make addressing this flaw a priority, especially for systems exposed to untrusted networks.

Generated by OpenCVE AI on October 9, 2026 at 17:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest OpENer release that includes a fix for the out‑of‑bounds read in the explicit messaging path; if an update is not feasible, ensure the affected service is isolated behind a firewall that restricts explicit messaging traffic.
  • Apply the specific commit 76b95cf patch to the source code or build a patched binary if the upstream release schedule is slow.
  • Monitor system logs for abnormal crashes or repeated message failures, and correlate them with external network activity to detect potential exploitation attempts.

Generated by OpenCVE AI on October 9, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Eipstackgroup
Eipstackgroup opener
Vendors & Products Eipstackgroup
Eipstackgroup opener

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in OpENer Enables Remote Denial of Service
Weaknesses CWE-125

Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N'}


Subscriptions

Eipstackgroup Opener
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T15:37:45.879Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T16:17:29.430

Modified: 2026-10-09T17:07:31.693

Link: CVE-2026-75345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:45:10Z

Weaknesses