CVE-2026-75353
Received Received - Intake

Out-of-Bounds Read in OpENer EtherNet/IP Parser

Vulnerability report for CVE-2026-75353, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

OpENer v2.3/ commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remtoe attacker to cause a denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75353 is an out-of-bounds read flaw in OpENer v2.3's EtherNet/IP ForwardOpen connection-path parser. The issue occurs in the ParseConnectionPath() function when processing a malformed ForwardOpen request. The function fails to validate the length of a trailing Simple Data segment against the remaining path budget, causing the remaining_path variable to underflow. This advances the message pointer beyond the request buffer, leading to a crash when GetPathSegmentType() dereferences the out-of-bounds pointer.

Detection Guidance

Detecting this vulnerability requires monitoring for crashes or unusual behavior in OpENer services handling EtherNet/IP traffic. Check logs for segmentation faults or service crashes after receiving ForwardOpen requests. Use network monitoring tools like Wireshark to inspect TCP port 44818 traffic for malformed packets. Enable core dumps on the system running OpENer to capture crash details for analysis.

Impact Analysis

This vulnerability allows a remote attacker to cause a denial of service by sending a specially crafted EtherNet/IP ForwardOpen request. The attack is network-reachable via TCP port 44818, meaning it can be exploited without local access. The crash occurs due to memory corruption from the out-of-bounds read, potentially disrupting services relying on the OpENer CIP stack.

Compliance Impact

This vulnerability causes a denial of service via network-reachable out-of-bounds read, which could disrupt critical operations in systems handling sensitive data. For GDPR, this may impact availability of data processing systems, potentially violating Article 32 requirements for resilience. For HIPAA, it could affect the availability of electronic protected health information systems, compromising Security Rule requirements.

Mitigation Strategies

Apply the patch provided in the OpENer GitHub issue to validate Simple Data segment lengths in the ParseConnectionPath function. Temporarily block or filter TCP port 44818 traffic at the network perimeter if OpENer is not required. Monitor for exploitation attempts by analyzing network traffic for malformed EtherNet/IP packets targeting this port.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75353. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart