CVE-2026-75350
Received Received - Intake

Buffer Overflow in EIPStackGroup OpENer

Vulnerability report for CVE-2026-75350, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in the GetAttributeList() function of EIPStackGroup OpENer v2.3 / master commit 76b95cf. It exists in the EtherNet/IP Get_Attribute_List service and allows a remote attacker to cause a denial of service by sending specially crafted requests.

Detection Guidance

To detect this vulnerability, monitor for crashes or memory corruption in OpENer's GetAttributeList() function when processing EtherNet/IP Get_Attribute_List service requests. Check for repeated requests targeting the same attribute (e.g., attribute 1 on Identity instance 1) with optional sockaddr info items (0x8000 and 0x8001).

Commands to detect: Use network monitoring tools like Wireshark to capture EtherNet/IP traffic and look for malformed GetAttributeList responses. Check OpENer logs for crashes or segmentation faults during explicit-message handling.

Impact Analysis

The vulnerability can lead to a denial of service, meaning an attacker could crash the affected system or service, disrupting normal operations. This could impact availability of systems using the vulnerable OpENer implementation.

Compliance Impact

This vulnerability, a buffer overflow in OpENer's GetAttributeList() function, could lead to denial of service attacks on industrial systems. Such disruptions may impact systems handling sensitive data, potentially violating compliance requirements for availability in standards like GDPR (Article 32) and HIPAA (Security Rule 164.308(a)(7)). However, specific compliance impacts depend on system context and data processed.

Mitigation Strategies

Update OpENer to a patched version beyond commit 76b95cf. If unavailable, restrict network access to EtherNet/IP services or disable the Get_Attribute_List service until a fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75350. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart