These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A use-after-free vulnerability exists in Systerel S2OPC up to 1.7.3. The impacted element is the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/subscription_mgr.c. This vulnerability allows remote attackers to exploit the system by manipulating the EventFilter argument. Users of Systerel S2OPC up to 1.7.3 should review and ap [truncated]
The CVE-2026-82618 vulnerability was determined in Systerel S2OPC up to 1.7.3, affecting the function set_range_matrix_on_string_array in src/Common/opcua_types/sopc_builtintypes.c. This function is part of the String Array Range Writing component and allows for an out-of-bounds read issue. The attack is possible to be carried out remotely. Organizations should be aware of this vulnerability and take nece [truncated]
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 during server-side EventFilter handling in CreateMonitoredItems processing, potentially allowing remote code execution. This vulnerability is critical as it could enable attackers to execute arbitrary code, leading to significant operational impacts. Defenders should assess exposure and prioritize potential mitigations or patches immedia [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T00:16:54.160Z and has not been modified since then. The vulnerability is a buffer overflow in Systerel S2OPC 1.7.3, allowing remote attackers to cause a denial of service via the AddNodes feature in address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server components. Organizat [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T23:16:53.997Z and has not been modified since then. CVE-2026-67867 is a Buffer Overflow vulnerability in Systerel S2OPC 1.7.3. This vulnerability allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data. User [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T23:16:53.887Z and has not been modified since then. This CVE-2026-67866 affects Systerel S2OPC 1.7.3 and involves a Buffer Overflow vulnerability. The vulnerability allows a remote attacker to cause a denial of service via specific paths. The issue may impact operational availability if exploited [truncated]
CVE-2026-9758 is a HIGH severity vulnerability with a CVSS score of 7.3. The vulnerability is caused by improper comparison with the certificates trusted list in S2OPC, which allows an attacker to provide a well-formed untrusted certificate to be considered trusted. The vulnerability was published on 2026-06-10T14:16:37.767Z and last modified on 2026-06-10T20:58:26.290Z.
CVE-2026-6899 is a MEDIUM severity vulnerability in the CycloneCrypto cryptographic wrapper of the S2OPC library. The issue is that the check for certificate revocation only considers the first matching Certificate Revocation List (CRL) and ignores other valid CRLs of the same Certificate Authority (CA). This could potentially allow a connection between an OPC UA client and server using a revoked certific [truncated]