CVE-2026-67859
Received Received - Intake

Buffer Overflow in open62541 v1.5.5 via Discovery/LDS

Vulnerability report for CVE-2026-67859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: MITRE

Description

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open62541 open62541 1.5.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a buffer overflow vulnerability in open62541 version 1.5.5. It allows a remote attacker to cause a denial of service by exploiting the Discovery/LDS handling mechanism.

Detection Guidance

Detecting this buffer overflow vulnerability in open62541 v1.5.5 requires monitoring for abnormal behavior in Discovery/LDS handling. Check for crashes, high CPU usage, or memory corruption in open62541 processes. Use network traffic analysis tools like Wireshark to inspect OPC UA discovery packets for malformed data.

Impact Analysis

An attacker could exploit this to crash the affected system, leading to service disruption and potential downtime for applications relying on open62541.

Compliance Impact

This vulnerability is a buffer overflow in open62541 v1.5.5 that allows remote attackers to cause denial of service. It does not directly impact data confidentiality or integrity but could disrupt system availability. Compliance impact depends on system role and data processed, but no specific regulatory violations are mentioned in the provided context.

Mitigation Strategies

Immediately upgrade open62541 to a patched version if available. If upgrading is not possible, disable the Discovery/LDS service if not required. Implement network segmentation to limit exposure. Monitor logs for signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart