CVE-2026-76988: liftoff-sr CIPster ForwardOpen cipconnectionmanager.cc forward_open out-of-bounds
A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forwardopen of the file cipconnectionmanager.cc of the component ForwardOpen Handler. Executing a manipulation of the argument productcode can lead to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ea870a274bf68dfaa3f511f20e2fff6778fb7b74. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892to a version that resolves this vulnerability.Patch ea870a274bf68dfaa3f511f20e2fff6778fb7b74
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be attacked remotely. The supplied severity vector indicates no privileges or user interaction are required.
How likely is exploitation?
A public exploit is available, so attackers could use it in attacks. Systems that expose the affected ForwardOpen handling remotely should be prioritized for remediation.
What should be done if the affected code is present?
Apply patch ea870a274bf68dfaa3f511f20e2fff6778fb7b74. The affected version identified in the data is 1802525be27d33e19a9a83c163e331a1d13b1892.