CVE-2026-82358
Deferred Deferred - Pending Action

CANopen SDO Write Protection Bypass in RT-Labs C-Open

Vulnerability report for CVE-2026-82358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rt-labs_ab c-open_canopen 1.1.1
rt-labs_ab c-open 1.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a write protection bypass in RT-Labs AB C-Open CANopen's SDO server implementation. It allows an unauthenticated attacker on the CAN bus to bypass read-only permissions by exploiting improper validation during SDO download-segment frame processing. The attacker can overwrite read-only Object Dictionary entries using two SDO frames without needing authentication.

Detection Guidance

Detecting this vulnerability requires monitoring CAN bus traffic for unauthorized SDO (Service Data Object) operations. Use tools like Wireshark with CAN protocol dissectors to inspect SDO frames. Look for SDO upload requests targeting read-only Object Dictionary entries followed by download-segment frames attempting writes. Check for any SDO sessions that bypass normal permission checks.

Impact Analysis

If you use RT-Labs AB C-Open CANopen in an environment where CANopen protocol operates over a CAN bus without authentication, an attacker could modify critical system configurations or data by overwriting read-only entries. This could lead to system malfunctions, unauthorized changes, or potential safety risks depending on the CANopen application.

Compliance Impact

This vulnerability allows unauthenticated attackers to overwrite read-only Object Dictionary entries via CAN bus, potentially altering system behavior or exposing sensitive data. Such unauthorized modifications could violate data integrity and confidentiality requirements in GDPR and HIPAA, as they may lead to unauthorized access or tampering with protected information.

Mitigation Strategies

Upgrade RT-Labs AB C-Open CANopen to version 1.1.1 or later, which fixes the SDO server write protection bypass. If upgrading is not immediately possible, isolate CANopen devices on a dedicated network segment to limit exposure. Monitor CAN bus traffic for suspicious SDO activity and implement strict access controls on Object Dictionary entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82358. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart