{"id":"CVE-2026-67861","published":"2026-08-04T22:17:16.460","lastModified":"2026-08-05T16:17:00.200","description":"An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-400"],"vendors":[],"products":[],"references":[{"url":"https://github.com/open62541/open62541/issues/8140","tags":[]},{"url":"https://raw.githubusercontent.com/open62541/open62541/v1.5.5/examples/custom_datatype/client_types_custom.c","tags":[]},{"url":"https://raw.githubusercontent.com/open62541/open62541/v1.5.5/src/client/ua_client_util.c","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8140","tags":[]}],"exploitRefs":[{"url":"https://github.com/open62541/open62541/issues/8140","tags":[]},{"url":"https://github.com/open62541/open62541/issues/8140","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a remote attacker to cause a denial of service by exploiting UA_Client_getRemoteDataTypes in open62541 versions prior to v.1.5.5, potentially disrupting system operations.","exploitability":"Exploitation requires access to the network and knowledge of the specific version affected; preconditions include the presence of vulnerable software components.","blast_radius":"If exploited, this could lead to a denial of service affecting the entire system or network segment where the affected component is deployed.","remediation":"Update open62541 to version v.1.5.5 or later to mitigate the risk.","tags":["dos","network","ics"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:55:52.156Z"}}