PatchSiren

EIPStackGroup CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review EIPStackGroup CVE published 2026-10-09

CVE-2026-75352

CVE-2026-75352 is a denial-of-service vulnerability in OpENer v2.3 due to an integer underflow in the EtherNet/IP ForwardOpen connection-path parser. The CVE record was published on 2026-10-09T00:00:00.000Z and has not been modified since then. This vulnerability allows remote attackers to cause disruptions. Defenders of industrial control systems using OpENer should assess exposure, prioritize verificati [truncated]

Review EIPStackGroup CVE published 2026-10-09

CVE-2026-75351

A CVE record describes an out-of-bounds read vulnerability in OpENer v2.3/commit 76b95cf, which allows a remote attacker to cause a denial of service via the server-side EtherNet/IP ForwardOpen connection-path parser. This vulnerability affects industrial control systems and environments using EtherNet/IP. Defenders should verify exposure and assess the need for updates or compensating controls. The CVE r [truncated]

HIGH EIPStackGroup CVE published 2026-10-09

CVE-2026-75350

CVE-2026-75350 is a buffer overflow vulnerability in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service in EIPStackGroup OpENer v2.3 / master commit 76b95cf. This allows a remote attacker to cause a denial of service. The vulnerability has a high CVSS score of 7.5, indicating significant risk. Defenders should assess exposure and prioritize verification and patching of af [truncated]

CRITICAL EIPStackGroup CVE published 2026-07-13

CVE-2026-51541

CVE-2026-51541 is an out-of-bounds read issue in OpENer 2.3.0 (commit 76b95cf) when handling malformed explicit requests with a forged EPath size in CIP message parsing. An attacker can send a valid ENIP SendRRData frame with a short CIP payload, claiming more path words are present than available, causing the parser to read beyond the stack receive buffer. This vulnerability exists in the CIP message par [truncated]

CRITICAL EIPStackGroup CVE published 2026-07-13

CVE-2026-51540

OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData). This vulnerability has a high impact on the affected systems, and users should be aware of this issue and take necessary precautions. The vulnerability is caused by an integer underflow in the processing of conne [truncated]

CRITICAL EIPStackGroup CVE published 2026-07-13

CVE-2026-51538

CVE-2026-51538 is an Incorrect Access Control vulnerability in EIPStackGroup OpENer 2.3.0 (commit 76b95cf). The vulnerability allows an attacker to bypass access controls using a valid session handle created by another legitimate client. This could lead to unauthorized access and potential exploitation of the affected system. Network administrators and security teams responsible for EIPStackGroup OpENer 2 [truncated]

CRITICAL EIPStackGroup CVE published 2026-07-13

CVE-2026-51537

CVE-2026-51537 OpENer 2.3.0 has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue affects OpENer 2.3.0 (commit 76b95cf) and may [truncated]

CRITICAL EIPStackGroup CVE published 2026-07-13

CVE-2026-51536

CVE-2026-51536 is a Stack Buffer Overflow vulnerability in OpENer 2.3.0. The issue arises from inconsistent integer typing when parsing CIP network packets. A maliciously crafted packet can cause a length parameter overflow or truncation, leading to a Stack Buffer Overflow. This vulnerability has a high potential impact due to the possibility of remote code execution. Organizations using OpENer 2.3.0 shou [truncated]

MEDIUM EIPStackGroup CVE published 2026-05-18

CVE-2026-38719

A medium-severity out-of-bounds read vulnerability exists in OpENer v2.3-558-g1e99582, an open-source EtherNet/IP stack implementation. The flaw resides in the Common Packet Format (CPF) parser within `CreateCommonPacketFormatStructure()` in `source/src/enet_encap/cpf.c`. An attacker can craft a malicious ENIP/CPF message with a manipulated `item_count` value that is not consistently validated against the [truncated]