Eipstackgroup

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    5
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-51541

    OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.

    Last Modified: Aug 11, 2026
    Published: Jul 13, 2026

    CVE-2026-51537

    OpENer: OpENer: Out-of-bounds read via malformed ForwardOpen requests

    Last Modified: Aug 11, 2026
    Published: Jul 13, 2026

    CVE-2026-51538

    EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.

    Last Modified: Aug 11, 2026
    Published: Jul 13, 2026

    CVE-2026-51536

    In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value. This negative length bypasses subsequent bounds checking (due to signed/unsigned comparison issues) and is ultimately used in memory operations, leading to a Stack Buffer Overflow when reading data in DecodePaddedEPath.

    Last Modified: Aug 11, 2026
    Published: Jul 13, 2026

    CVE-2026-51540

    Memory Corruption via Integer Underflow in OpENer SendUnitData

    Last Modified: Aug 11, 2026
    Published: Jul 13, 2026
    Items Per Page
    Eipstackgroup Vulnerabilities & Security CVEs | CVE-DB