CVE-2026-75347
Deferred Deferred - Pending Action

Expired Pointer Dereference in EIPStackGroup OpENer

Vulnerability report for CVE-2026-75347, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an expired pointer dereference issue in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf. It exists in the EtherNet/IP Common Packet Format handling logic and allows a remote attacker to cause a denial of service by exploiting this flaw.

Detection Guidance

Detecting CVE-2026-75347 requires monitoring for stack-use-after-return conditions in OpENer's CPF handling. Use AddressSanitizer (ASan) during compilation to detect memory corruption. Monitor network traffic for malformed EtherNet/IP packets with inconsistent item counts between TCP/UDP sessions. Check for crashes or protocol confusion in OpENer logs when processing crafted packets.

Impact Analysis

The vulnerability can lead to a denial of service, meaning an attacker could crash the affected system or application, disrupting its normal operation and potentially causing downtime or loss of service.

Compliance Impact

This vulnerability causes denial of service through expired pointer dereference, which could lead to system instability or crashes. For compliance with standards like GDPR or HIPAA, such disruptions may violate availability requirements, potentially leading to unauthorized access or data processing interruptions. However, the specific impact depends on system configuration and deployment context.

Mitigation Strategies

Update OpENer to a version beyond commit 76b95cf or apply patches addressing the expired pointer dereference in EtherNet/IP CPF handling. Disable exposed EtherNet/IP services if not required and monitor network traffic for anomalous CPF packets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75347. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart