Impact
The flaw resides in the set_range_matrix_on_string_array function in the String Array Range Writing component of Systerel S2OPC. An attacker can trigger an out‑of‑bounds read that allows the process to read memory outside the intended buffer, potentially leaking internal data or destabilizing the application. The vulnerability is classified as a classic bounds‑checking error (CWE-119 and CWE-125).
Affected Systems
Any installation of Systerel S2OPC version 1.7.3 or older is affected; the product is the S2OPC OPC UA stack provided by Systerel.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. EPSS data is not available, and the vulnerability is not in the CISA KEV catalog. The description notes that the attack is feasible remotely, but the impact is limited to memory disclosure or a crash rather than code execution. The risk is therefore moderate, with a realistic chance of exploitation if exposed to the public network.
OpenCVE Enrichment