Impact
The vulnerability lies in the TSnap7MicroClient::opUpload function of the snap7 library. By manipulating the DataLen argument, an attacker can cause a heap overflow that corrupts memory. The flaw is identified as CWE‑119, a classic buffer overrun, and can lead to arbitrary code execution, a denial of service, or other integrity violations.
Affected Systems
Products affected are davenardella snap7 releases up to and including version 1.4.3, as well as any prior releases. Any installation that exposes the snap7 service to a network without proper isolation remains vulnerable. No patch has been issued by the vendor to date.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, while the EPSS score of less than 1 % suggests that automated, widespread exploitation is presently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, as stated in the description. Based on the low EPSS and the absence of an official fix, it is inferred that large‑scale exploitation is not imminent, but the lack of vendor response introduces uncertainty about future targeted attacks.
OpenCVE Enrichment