Executive brief
OpENer is an open-source software stack used by industrial devices to communicate over EtherNet/IP networks. A security flaw in how the software handles incoming data packets could allow an attacker to crash the device by sending a specially crafted message. This could lead to a loss of communication or control in industrial environments, potentially disrupting operations.
Technical details
An out-of-bounds read vulnerability exists in the CreateCommonPacketFormatStructure() function within source/src/enet_encap/cpf.c of OpENer. The vulnerability is caused by insufficient validation of the 'item_count' field in the Common Packet Format (CPF) header against the actual length of the data slice. An attacker can provide a large, malicious item_count value, causing the parser to continue reading structured fields beyond the allocated buffer (cpf_start + data_length). While the CVSS vector provided by CISA-ADP suggests a local attack vector (AV:L), the component is part of a network encapsulation layer (ENIP/CPF), typically reachable over the network. Exploitation leads to a denial-of-service (crash) via a heap-buffer-overflow.
Affected products
- EIPStackGroup OpENer v2.3-558-g1e99582
Timeline
- 2026-03-25: other: Issue reported on GitHub
- 2026-05-18: advisory: CVE published and NVD record created