Description
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Update
AI Analysis

Impact

An out‑of‑bounds read in the server‑side CIP SetAttributeList service of the OpENer project allows a remote attacker to trigger a denial‑of‑service condition. The flaw reads beyond allocated memory, which can corrupt the process state and force the server to crash or become unresponsive. The impact is limited to availability, with no disclosed information about confidentiality or integrity compromise.

Affected Systems

Systems running EIPStackGroup OpENer version 2.3 or the master branch before commit 76b95cf are affected. Any deployment of these versions that exposes the SetAttributeList service to untrusted networks is vulnerable.

Risk and Exploitability

The vulnerability is exploitable remotely, as the vulnerable service listens for external requests. No exploit probability score is published and the issue is not listed in the CISA KEV catalog. Although the EPSS value is unavailable, the fact that the flaw induces a DoS attack vector makes it a high‑impact risk for exposed services. Remediation requires applying a newer code revision that fixes the bounds check.

Generated by OpenCVE AI on October 9, 2026 at 17:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade EIPStackGroup OpENer to a version that includes commit 76b95cf or later, ensuring the out-of-bounds read is corrected.
  • Restrict access to the CIP SetAttributeList endpoint by placing it behind a firewall or VPN so that only trusted hosts can reach it.
  • Configure rate limiting or connection throttling on the CIP service to mitigate automated DoS attempts and reduce the impact of any accidental exploit attempts.

Generated by OpenCVE AI on October 9, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Leading to Denial of Service in OpENer CIP SetAttributeList
Weaknesses CWE-787

Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T15:48:40.561Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75346

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T16:17:29.590

Modified: 2026-10-09T16:40:29.800

Link: CVE-2026-75346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:30:08Z

Weaknesses