CVE-2026-82357
Deferred Deferred - Pending Action

NULL Pointer Dereference in RT-Labs C-Open CANopen

Vulnerability report for CVE-2026-82357, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rt-labs_ab c-open_canopen 1.1.1
rt-labs_ab c-open 1.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

RT-Labs AB C-Open CANopen has a NULL pointer dereference flaw when using the LSS protocol for device configuration. If the device's identity object (0x1018) lacks required subindexes, an unauthenticated remote attacker on the CAN bus can trigger the LSS protocol, crash the device, and potentially cause denial of service.

Detection Guidance

This vulnerability involves a NULL pointer dereference in RT-Labs AB C-Open CANopen when the LSS protocol is used with a misconfigured identity object. Detection requires checking if the device's identity object (0x1018) has all required subindexes. No specific commands are provided in the context, but monitoring for crashes during LSS protocol interactions may indicate exploitation.

Impact Analysis

This vulnerability allows an attacker to crash the device by exploiting the LSS protocol, leading to potential system downtime or operational disruption. It requires access to the CAN bus, such as through a compromised node, but does not require authentication.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized remote attacks on CAN bus-connected devices, leading to system crashes. Such disruptions may compromise data integrity or availability, which are critical under these regulations.

Mitigation Strategies

Upgrade to version 1.1.1 of RT-Labs AB C-Open CANopen, as it fixes CVE-2026-82357. Ensure the identity object (0x1018) is properly configured with all required subindexes to prevent NULL pointer dereference during LSS protocol use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82357. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart