CVE-2026-67857
7.5 HIGHpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows out-of-bounds read in open62541 1.5.5, potentially leading to information disclosure. It matters because attackers can exploit this to gain sensitive data.
- Exploitability
- Exploitation requires specific client-side interaction but is considered feasible by skilled adversaries.
- Blast radius
- If exploited, it could impact systems using open62541 for industrial control or critical infrastructure, leading to potential operational disruptions.
- Prioritized remediation
- Update to open62541 version 1.6.0 or later which addresses this vulnerability.
icsinfo-discclient-side
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-125
Public exploit & PoC references
- https://github.com/gff-cw/information/issues/9
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c
- https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c
- https://github.com/open62541/open62541/issues/8104
- https://github.com/open62541/open62541/issues/8104
All references
- https://github.com/gff-cw/information/issues/9
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect.c
- https://github.com/open62541/open62541/blob/v1.5.5/examples/client_connect_loop.c
- https://github.com/open62541/open62541/blob/v1.5.5/src/client/ua_client_connect.c
- https://github.com/open62541/open62541/issues/8104
- https://github.com/open62541/open62541/issues/8104
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.