Executive brief
CIPster is an Ethernet/IP protocol stack used in industrial I/O adapter devices. A memory corruption vulnerability in the attribute handling logic allows a remote attacker to read arbitrary memory or write out of bounds, potentially compromising device availability and control.
Technical details
The vulnerability is a buffer overflow in the CipAttribute::GetAttrData and CipAttribute::SetAttrData functions (ciptypes.h). The root cause is insufficient bounds checking on byte-array attribute length: a remote attacker can send a SetAttributeSingle message with an attacker-controlled length value that is not validated against the actual buffer capacity. This allows out-of-bounds reads (information disclosure) and out-of-bounds writes (memory corruption). The attack is network-reachable and requires no authentication. The patch (commit e745d9d4a8ca3a13689066983a1269fe1e567674) introduces a CipByteArray type that tracks capacity immutably, preventing length inflation past the allocation.
Affected products
- liftoff-sr CIPster before commit e745d9d4a8ca3a13689066983a1269fe1e567674
Timeline
- 2026-08-20: disclosed
- 2026-06-01: patched: Patch commit e745d9d4a8ca3a13689066983a1269fe1e567674