Description
Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

This vulnerability is an out-of-bounds write in the CONPROSYS nano Series firmware. A specially crafted request sent by a remote attacker can cause the system to crash, leading to a denial-of-service condition. The weakness is identified as CWE-787 and could be leveraged to stop the normal operation of the affected device.

Affected Systems

The affected devices are Contec Co., Ltd. programmable remote I/O coupler units of the CONPROSYS nano Series, specifically the CPSN-PCB271-S1-041, the CPSN‑EOB471EI‑[]1 Ethernet/IP Adapter, and the CPSN‑MCB271‑* server‑type units. No specific firmware or software versions were provided in the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attacker must send a crafted packet over the network interface to trigger the overflow; the attack vector is therefore remote network access. No specific conditions are listed beyond the ability to send a malformed request.

Generated by OpenCVE AI on September 14, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware or software of the affected Contec remote I/O coupler units to the latest version that fixes the out-of-bounds write.
  • If a firmware update is not immediately available, restrict external network connectivity to the units by placing them behind a firewall and limiting open ports to only those required for normal operation.
  • Continuously monitor the units for abnormal behavior such as service restarts or crash logs, and apply any new vendor patches promptly.

Generated by OpenCVE AI on September 14, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causing DoS in CONPROSYS Nano Series Remote I/O Coupler Units

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causing DoS in CONPROSYS Nano Series Remote I/O Coupler Units

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T11:19:47.629Z

Reserved: 2026-08-31T02:30:58.278Z

Link: CVE-2026-82782

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:07.387Z

cve-icon NVD

Status : Received

Published: 2026-09-14T07:17:19.943

Modified: 2026-09-14T12:17:48.577

Link: CVE-2026-82782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T21:30:08Z

Weaknesses