Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67869

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

A flaw was found in open62541. A remote attacker can exploit a buffer overflow vulnerability within the Service_Call function. This vulnerability arises from improper validation of input arguments against runtime-resolved InputArguments metadata, which can lead to a denial of service (DoS).

Отчет

This Important flaw in open62541 allows a remote, unauthenticated attacker to trigger a denial of service. The vulnerability stems from insufficient validation of input arguments within the Service_Call function, which can lead to a buffer overflow and subsequent service unavailability.

Меры по смягчению последствий

No practical workaround identified beyond restricting NodeManagement / method-metadata changes to trusted principals and limiting network exposure of the OPC UA server.

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2511858open62541: open62541: Denial of Service via buffer overflow in Service_Call

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
27 дней назад

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

CVSS3: 7.5
nvd
27 дней назад

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

CVSS3: 7.5
debian
27 дней назад

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote atta ...

CVSS3: 7.5
github
27 дней назад

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

7.5 High

CVSS3