Executive brief
open62541 is an open-source OPC UA server implementation used in industrial automation and IoT systems for device communication and discovery. A buffer overflow vulnerability in the Local Discovery Server (LDS) component allows a remote attacker to trigger a denial of service by sending specially crafted discovery packets, potentially causing the server to crash and disrupting critical industrial operations.
Technical details
A buffer overflow vulnerability exists in open62541 v1.5.5 within the Discovery/LDS (Local Discovery Server) handling mechanism. The vulnerability is triggered via malformed discovery protocol messages that exceed buffer boundaries in the LDS processing logic. An attacker on the network can send crafted packets to the discovery service without authentication to trigger the overflow, causing abnormal process termination. While currently classified as a denial-of-service vector, buffer overflows can potentially be exploited for code execution depending on memory layout and protections. Patches are expected to be available in subsequent releases.
Affected products
- open62541 open62541 v1.5.5
Timeline
- 2026-08-04: disclosed