cbcvebase.
CVE-2026-51537
published 2026-07-13

CVE-2026-51537: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short…

PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.65%
48.9th percentile
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianpython3.14——
opener_projectopener——
rust-langrust——

Detection & IOCsextracted from sources · hover to see the quote

  • →Detect malformed CIP ForwardOpen/LargeForwardOpen requests carried within a valid ENIP outer frame — look for ENIP frames where the CIP payload is shorter than the minimum required for a ForwardOpen request, which would cause the parser to read beyond the buffer. ↗
  • →Monitor for unauthenticated network traffic targeting EtherNet/IP (ENIP) services (default port 44818 TCP/UDP) with short/truncated CIP ForwardOpen payloads, which may indicate exploitation attempts against OpENer 2.3.0 (commit 76b95cf). ↗
  • →Alert on out-of-bounds read conditions or crashes in the OpENer Connection Manager component when processing ForwardOpen requests, which may indicate denial of service or information disclosure exploitation. ↗
  • ·The vulnerability is confirmed in OpENer version 2.3.0 at a specific commit; defenders should verify the exact commit hash of deployed OpENer instances to confirm exposure. ↗
  • ·No authentication is required to trigger this vulnerability, meaning any network-reachable attacker can attempt exploitation — network segmentation and firewall rules restricting ENIP access are critical mitigations. ↗

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.