


Perceptive Security
SOC/SIEM Consultancy

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_…
Published:
5 August 2026 at 22:00:00
Alert date:
6 August 2026 at 14:02:41
Source:
nvd.nist.gov
Critical Infrastructure, Network Infrastructure
A buffer overflow vulnerability has been identified in Systerel S2OPC version 1.7.3, an OPC-UA toolkit. The vulnerability allows a remote attacker to trigger a denial of service condition. The flaw is present in multiple components including the AddNodes service, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server. The vulnerability is tracked as CVE-2026-67871 and is documented in the NVD. Relevant source files are available on GitHub and issues are tracked on GitLab. Exploitation does not require authentication, making this a remotely exploitable denial of service risk. The affected product is used in industrial and critical infrastructure OPC-UA communication contexts.
Technical details
Mitigation steps:
Affected products:
Systerel S2OPC 1.7.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67871
https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/address_space/internal/sopc_node_mgt_helper_internal.c
https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/address_space_bs.c
https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/tests/ClientServer/CMakeLists.txt
https://gitlab.com/systerel/S2OPC/-/work_items/1787
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
