top of page
perceptive_background_267k.jpg

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

Published:

3 augustus 2026 om 22:00:00

Alert date:

4 augustus 2026 om 23:03:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Mobile & IoT, Network Infrastructure

CVE-2026-67861 is a vulnerability affecting open62541 version 1.5.5 and earlier, an open-source OPC UA implementation. A remote attacker can exploit the UA_Client_getRemoteDataTypes component to cause a denial of service condition. The vulnerability is remotely exploitable without requiring authentication. The issue has been documented on the open62541 GitHub repository. Affected code paths include the client utility functions in ua_client_util.c and related custom datatype handling examples. Given the industrial and IoT context of OPC UA, this vulnerability may affect critical infrastructure environments. Users are advised to review the referenced GitHub issue and update to a patched version when available.

Technical details

Mitigation steps:

Affected products:

open62541 v1.5.5 and before

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page