{"id":"CVE-2026-67859","published":"2026-08-04T22:17:16.223","lastModified":"2026-08-05T16:17:00.067","description":"Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-120"],"vendors":[],"products":[],"references":[{"url":"https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/util/ua_util.c","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8095","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8095","tags":[]}],"exploitRefs":[{"url":"https://github.com/open62541/open62541/blob/master/examples/discovery/server_lds.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_discovery_mdns.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/server/ua_services_discovery.c","tags":[]},{"url":"https://github.com/open62541/open62541/blob/master/src/util/ua_util.c","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8095","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8095","tags":[]}],"hasPoc":true,"ai":{"summary":"A buffer overflow vulnerability in open62541 v1.5.5 can be exploited by a remote attacker to cause a denial of service through the Discovery/LDS handling process.","exploitability":"Exploitation requires access to the Discovery/LDS handling mechanism, which may be difficult but not impossible for an attacker with network reach.","blast_radius":"If exploited, this vulnerability could lead to a complete system crash affecting the device or server running open62541 v1.5.5.","remediation":"Update to a patched version of open62541 or apply vendor-provided patches immediately.","tags":["buffer-overflow","denial-of-service","remote-exploit","ics"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:55:38.659Z"}}