top of page
perceptive_background_267k.jpg

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

Published:

3 augustus 2026 om 22:00:00

Alert date:

4 augustus 2026 om 23:03:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure, Network Infrastructure

CVE-2026-67857 affects open62541 version 1.5.5, an open-source OPC UA implementation widely used in industrial and IoT environments. The vulnerability is an out-of-bounds read located in the client-side function responseReadNamespacesArray() within src/client/ua_client_connect.c. This type of memory safety issue can potentially lead to information disclosure or application crashes when a malicious server sends a crafted response. The flaw is triggered during the client connection phase when namespace arrays are being read and processed. References include GitHub issues and source code links pointing to the exact affected files. The vulnerability has been assigned a high criticality level, suggesting significant risk to systems using this library version.

Technical details

Mitigation steps:

Affected products:

open62541 1.5.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page