Open62541
Open62541: vulnerabilidades y CVE
Open62541 tiene 25 vulnerabilidades publicadas, 22 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses22
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82623 | Media (5.5) | 0.70% | — | 31 ago 2026 | A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component… |
| CVE-2026-67870 | Crítica (9.8) | 1.1% | — | 6 ago 2026 | In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty… |
| CVE-2026-67869 | Alta (7.5) | 0.82% | — | 6 ago 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata |
| CVE-2026-67863 | Alta (7.5) | 0.74% | — | 5 ago 2026 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes… |
| CVE-2026-67864 | Alta (7.5) | 0.76% | — | 5 ago 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component |
| CVE-2026-67862 | Alta (7.5) | 0.58% | — | 4 ago 2026 | open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service. |
| CVE-2026-67861 | Alta (7.5) | 0.75% | — | 4 ago 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component |
| CVE-2026-67860 | Alta (7.5) | 0.46% | — | 4 ago 2026 | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend. |
| CVE-2026-67859 | Alta (7.5) | 0.82% | — | 4 ago 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling. |
| CVE-2026-67858 | Alta (7.5) | 0.86% | — | 4 ago 2026 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a… |
| CVE-2026-67857 | Alta (7.5) | 0.63% | — | 4 ago 2026 | open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. |
| CVE-2026-67856 | Alta (7.5) | 0.76% | — | 4 ago 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions… |
| CVE-2026-67855 | Alta (7.5) | 0.51% | — | 4 ago 2026 | open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service. |
| CVE-2026-18785 | Baja (1.9) | 0.16% | — | 4 ago 2026 | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a… |
| CVE-2026-18784 | Baja (1.9) | 0.17% | — | 4 ago 2026 | A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based… |
| CVE-2026-65423 | Alta (8.7) | 0.80% | — | 30 jul 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write. |
| CVE-2026-63362 | Alta (8.2) | 1.8% | — | 30 jul 2026 | An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet. |
| CVE-2026-63035 | Alta (7.2) | 0.76% | — | 30 jul 2026 | A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code. |
| CVE-2026-63559 | Alta (8.7) | 0.70% | — | 30 jul 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information. |
| CVE-2026-15690 | Baja (1.3) | 0.44% | — | 14 jul 2026 | A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such… |
| CVE-2026-11946 | Alta (7.5) | 0.52% | — | 2 jul 2026 | An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an… |
| CVE-2026-33592 | Alta (7.5) | 0.52% | — | 2 jul 2026 | An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can… |
| CVE-2024-53429 | Alta (7.5) | 0.74% | — | 21 nov 2024 | Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash. |
| CVE-2022-25761 | Alta (7.5) | 1.4% | — | 23 ago 2022 | The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all… |
| CVE-2020-36429 | Media (5.5) | 0.31% | — | 20 jul 2021 | Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.