Description
A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption that may allow code execution or service disruption
Action: Assess Impact
AI Analysis

Impact

The vulnerability lies in the TSnap7MicroClient::opUpload function of the snap7 library. By manipulating the DataLen argument, an attacker can cause a heap overflow that corrupts memory. The flaw is identified as CWE‑119, a classic buffer overrun, and can lead to arbitrary code execution, a denial of service, or other integrity violations.

Affected Systems

Products affected are davenardella snap7 releases up to and including version 1.4.3, as well as any prior releases. Any installation that exposes the snap7 service to a network without proper isolation remains vulnerable. No patch has been issued by the vendor to date.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, while the EPSS score of less than 1 % suggests that automated, widespread exploitation is presently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, as stated in the description. Based on the low EPSS and the absence of an official fix, it is inferred that large‑scale exploitation is not imminent, but the lack of vendor response introduces uncertainty about future targeted attacks.

Generated by OpenCVE AI on September 15, 2026 at 17:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the most recent snap7 release that implements bounds checking for DataLen in TSnap7MicroClient::opUpload; if no such release exists, apply a local patch that validates DataLen before copying data.
  • Restrict inbound traffic to the snap7 service so that only trusted clients or VPN tunnels can reach it, thereby limiting the attack surface.
  • If the opUpload operation is not required for your workflow, disable it or configure the application to reject any incoming opUpload requests.

Generated by OpenCVE AI on September 15, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title davenardella snap7 s7_micro_client.cpp opUpload memory corruption
First Time appeared Davenardella
Davenardella snap7
Weaknesses CWE-119
CPEs cpe:2.3:a:davenardella:snap7:*:*:*:*:*:*:*:*
Vendors & Products Davenardella
Davenardella snap7
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Davenardella Snap7
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:33.063Z

Reserved: 2026-09-12T16:11:37.054Z

Link: CVE-2026-90572

cve-icon Vulnrichment

Updated: 2026-09-15T13:50:53.158Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T18:16:48.727

Modified: 2026-09-15T15:17:28.670

Link: CVE-2026-90572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer