CVE-2026-75345
Received Received - Intake

Out-of-Bounds Read in OpENer Stack

Vulnerability report for CVE-2026-75345, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75345 is an out-of-bounds read vulnerability in OpENer v2.3.0. It occurs in the unconnected explicit messaging path when processing crafted requests with an overlong Padded EPath. The vulnerability allows a remote attacker to cause a denial of service by crashing the process through an AddressSanitizer-confirmed out-of-bounds read.

Detection Guidance

To detect this vulnerability, monitor for crashes or denial-of-service events in OpENer-based systems handling EtherNet/IP traffic. Use network traffic analysis tools like Wireshark to inspect TCP port 44818 for malformed requests with overlong Padded EPath. Enable AddressSanitizer or similar tools during compilation to catch out-of-bounds reads.

Impact Analysis

This vulnerability can be exploited remotely without authentication via TCP port 44818. An attacker could crash the OpENer-based device, leading to a denial of service. This may disrupt industrial automation systems relying on EtherNet/IP communication.

Compliance Impact

This vulnerability, an out-of-bounds read in OpENer v2.3.0, could lead to denial-of-service conditions in industrial control systems. Such disruptions may impact systems handling sensitive data, potentially violating compliance with standards like GDPR (data integrity) or HIPAA (availability of critical systems). However, the provided context does not explicitly link this vulnerability to specific compliance failures.

Mitigation Strategies

Immediately update OpENer to a patched version beyond commit 76b95cf. If updating is not possible, restrict network access to TCP port 44818 using firewalls. Disable unauthenticated explicit messaging paths if feasible. Monitor vendor advisories for official patches or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75345. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart