Impact
S2OPC through version 1.7.3 suffers a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items(); when an allocation for DataChangeNotification fails, a later successful allocation for EventNotificationList overwrites the null pointer. This causes the server process to crash, resulting in a denial of service. The weakness is a classic null pointer dereference mapped to CWE‑476.
Affected Systems
The affected product is Systerel S2OPC, all releases up to and including 1.7.3. The flaw impacts any instance of the toolkit that processes OPC UA sessions capable of both data‑change and event notifications, such as OPC UA servers or clients built on this toolkit.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate severity. The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation is known. Attackers can trigger heap allocation failures through external OPC UA clients that initiate a subscription containing both data‑change and event notifications, leading to a server crash. The impact is confined to availability, with no remote code execution or privilege escalation.
OpenCVE Enrichment