CVE-2026-51541
published 2026-07-13CVE-2026-51541: OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An…
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.42%
36.1th percentile
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opener_project | opener | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size.
ghsa_unreviewed·2026-07-14
CVE-2026-51541 [CRITICAL] CWE-125 OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size.
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.
VulDB
OpENer 2.3.0 CIP Message Parsing path_size out-of-bounds
vuldb·2026-07-14
CVE-2026-51541 [LOW] OpENer 2.3.0 CIP Message Parsing path_size out-of-bounds
A vulnerability was found in OpENer 2.3.0 and classified as problematic. The affected element is an unknown function of the component CIP Message Parsing. The manipulation of the argument path_size results in out-of-bounds read.
This vulnerability is identified as CVE-2026-51541. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-13
Published