Opener Project Opener vulnerabilities
16 known vulnerabilities affecting opener_project/opener.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH7
Vulnerabilities
Page 1 of 1
CVE-2022-43604P2CRITICALCVSS 9.8fixed in 2022-10-182023-03-16
CVE-2022-43604 [CRITICAL] CWE-787 CVE-2022-43604: An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request function
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of Ethe
nvd
CVE-2022-43605P2CRITICALCVSS 9.8fixed in 2022-10-182023-03-16
CVE-2022-43605 [CRITICAL] CWE-787 CVE-2022-43605: An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request function
An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of Ethe
nvd
CVE-2020-13556P2CRITICALCVSS 9.8v2.32020-12-11
CVE-2020-13556 [CRITICAL] CWE-787 CVE-2020-13556: An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Gro
An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
nvd
CVE-2026-51537P2CRITICALCVSS 9.1v2.3.02026-07-13
CVE-2026-51537 [CRITICAL] CWE-125 CVE-2026-51537: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager ha
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data
nvd
CVE-2026-51538P3CRITICALCVSS 9.1v2.3.02026-07-13
CVE-2026-51538 [CRITICAL] CWE-284 CVE-2026-51538: EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability i
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specifi
nvd
CVE-2026-51536P3CRITICALCVSS 9.1v2.3.02026-07-13
CVE-2026-51536 [CRITICAL] CWE-190 CVE-2026-51536: In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network pack
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). If a maliciously crafted packet wit
nvd
CVE-2021-21777P3CRITICALCVSS 10.0v2.32021-06-17
CVE-2021-21777 [CRITICAL] CWE-125 CVE-2021-21777: An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP S
An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read.
nvd
CVE-2026-51541P3CRITICALCVSS 9.1v2.3.02026-07-13
CVE-2026-51541 [CRITICAL] CWE-125 CVE-2026-51541: OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling m
OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the par
nvd
CVE-2026-51540P3CRITICALCVSS 9.8v2.3.02026-07-13
CVE-2026-51540 [CRITICAL] CWE-191 CVE-2026-51540: OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue
OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).
nvd
CVE-2022-43606P3HIGHCVSS 7.5fixed in 2022-10-182023-03-16
CVE-2022-43606 [HIGH] CWE-824 CVE-2022-43606: A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry
A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerabilit
nvd
CVE-2021-27482P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27482 [HIGH] CWE-125 CVE-2021-27482: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data.
nvd
CVE-2020-13530P3HIGHCVSS 7.5v2.32020-12-11
CVE-2020-13530 [HIGH] CWE-910 CVE-2020-13530: A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Gr
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.
nvd
CVE-2021-27500P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27500 [HIGH] CWE-617 CVE-2021-27500: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
nvd
CVE-2021-27498P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27498 [HIGH] CWE-617 CVE-2021-27498: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
nvd
CVE-2021-27478P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27478 [HIGH] CWE-681 CVE-2021-27478: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition.
nvd
CVE-2022-32434P3HIGHCVSS 7.8v2.3.02022-07-15
CVE-2022-32434 [HIGH] CWE-787 CVE-2022-32434: EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSI
EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSIX/OpENer+0x56073d.
nvd