Impact
An out‑of‑bounds read in the server‑side CIP SetAttributeList service of the OpENer project allows a remote attacker to trigger a denial‑of‑service condition. The flaw reads beyond allocated memory, which can corrupt the process state and force the server to crash or become unresponsive. The impact is limited to availability, with no disclosed information about confidentiality or integrity compromise.
Affected Systems
Systems running EIPStackGroup OpENer version 2.3 or the master branch before commit 76b95cf are affected. Any deployment of these versions that exposes the SetAttributeList service to untrusted networks is vulnerable.
Risk and Exploitability
The vulnerability is exploitable remotely, as the vulnerable service listens for external requests. No exploit probability score is published and the issue is not listed in the CISA KEV catalog. Although the EPSS value is unavailable, the fact that the flaw induces a DoS attack vector makes it a high‑impact risk for exposed services. Remediation requires applying a newer code revision that fixes the bounds check.
OpenCVE Enrichment