9.1
CVE-2026-51537
- EPSS 0.48%
- Veröffentlicht 13.07.2026 00:00:00
- Zuletzt bearbeitet 11.08.2026 16:42:16
- CVE-Watchlists
- Unerledigt
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opener Project ≫ Opener Version2.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.391 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://github.com/EIPStackGroup/OpENer/issues/564
https://gist.github.com/MrAlaskan/a5fb0fb7765c9df80d28220ed558f04e