CVE-2026-82358: RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass
RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/cosdoserver.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RT-Labs AB C-Open CANopento a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send CANopen traffic on the CAN bus can exploit it. CANopen does not provide built-in authentication mechanisms.
What does an attacker need to send?
The attacker can initiate an SDO upload for a read-only Object Dictionary entry and then send download-segment frames targeting the resulting data pointer. The issue can be triggered using two SDO frames.
Which release fixes the issue?
RT-Labs AB C-Open CANopen version 1.1.1 includes the fix.