Executive brief
EIPStackGroup OpENer is an open-source implementation of the EtherNet/IP protocol used in industrial automation to allow devices like controllers and sensors to communicate. A security flaw in how the software manages user sessions allows an attacker to hijack or terminate active connections between legitimate industrial equipment. This could lead to unauthorized control of industrial processes or a complete shutdown of communication between critical devices on the factory floor.
Technical details
An improper access control vulnerability (CWE-284) exists in OpENer 2.3.0 (commit 76b95cf) within the encapsulation session handling logic in 'source/src/enet_encap/encap.c'. The 'CheckRegisteredSessions' function verifies if a session handle is active but fails to validate if the handle belongs to the specific TCP socket issuing the request. Because session handles are generated as predictable small integers, a remote, unauthenticated attacker can enumerate active handles and include them in forged encapsulation commands (such as 'SendRRData' or 'UnregisterSession'). This allows the attacker to perform session hijacking or trigger a cross-connection Denial of Service (DoS) by unilaterally terminating legitimate client connections.
Affected products
- EIPStackGroup OpENer 2.3.0 (commit 76b95cf)
Timeline
- 2026-04-23: disclosed: Issue reported on GitHub repository
- 2026-07-09: advisory: Detailed security advisory published by researcher
- 2026-07-13: advisory: CVE published to NVD