Executive brief
Snap7 is a library used to communicate with industrial PLC (Programmable Logic Controller) devices via the S7 protocol. A malicious or compromised PLC can send a specially crafted response to trigger memory corruption in the client application, potentially causing crashes or allowing attackers to read sensitive data from memory.
Technical details
The vulnerability exists in the TSnap7MicroClient::opUpload() function in src/core/s7_micro_client.cpp, where the function derives the length of a memcpy operation from a server-supplied S7 DataLen header field without validating it. An attacker controlling the PLC server or positioned on the S7 network can craft a response with an invalid DataLen value, leading to either a negative-size memcpy or an out-of-bounds read/write. The vulnerability is reachable on the first Upload response with no prior multi-slice sequence required. Three issues are unchecked: the sign of the Size variable, Size validation against bytes actually received, and validation of Offset + Size against the destination buffer capacity (opData, a 65536-byte buffer). Patches are not yet available as the maintainers have not responded to the issue report.
Affected products
- davenardella snap7 up to 1.4.3
Timeline
- 2026-08-01: disclosed
- 2026-09-13: advisory