CVE-2026-51536: Buffer Overflow
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value. This negative length bypasses subsequent bounds checking (due to signed/unsigned comparison issues) and is ultimately used in memory operations, leading to a Stack Buffer Overflow when reading data in DecodePaddedEPath.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthenticated attacker who can send crafted CIP network packets to a vulnerable OpENer instance can trigger the issue. The CVSS vector indicates network reachability, low attack complexity, and no user interaction are required.
What is the practical impact of successful exploitation?
Processing a malicious packet can cause a stack buffer overflow in DecodePaddedEPath. The reported CVSS metrics indicate high confidentiality impact and high availability impact, while integrity impact is rated none.
How can I determine whether an instance is affected?
The affected version identified in the available data is OpENer 2.3.0 at commit 76b95cf. Review the deployed source version or commit and assess whether the instance accepts incoming CIP network packets.
What can be done if updating is not immediately possible?
Restrict network access to the CIP service so untrusted systems cannot send packets to the OpENer instance. Because exploitation requires network packet delivery and no authentication, network segmentation and access controls are the available mitigations supported by the provided data.