CVE-2026-82618: Systerel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-bounds
A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function setrangematrixonstringarray of the file src/Common/opcuatypes/sopcbuiltintypes.c of the component String Array Range Writing. This manipulation causes out-of-bounds read. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered affected?
Systerel S2OPC versions up to and including 1.7.3 are identified as affected. The vulnerable code is in the String Array Range Writing functionality.
What level of access does an attacker need?
The attack can be carried out remotely, and the supplied vector indicates network access with low privileges and no user interaction. The available data does not identify the specific service exposure or authentication path required.
What is the likely impact?
The described flaw causes an out-of-bounds read, with availability impact rated low and no stated confidentiality or integrity impact. The supplied severity score is 4.3 (medium).
Is a fix available?
No fix or patched version is provided in the available data. The project was reportedly notified through an issue report but had not responded at the time of publication.