Opener Project
Opener Project Opener: vulnerabilidades y CVE
Opener Project Opener tiene 16 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses5
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-51541 | Crítica (9.1) | 0.55% | — | 13 jul 2026 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very… |
| CVE-2026-51540 | Crítica (9.8) | 0.57% | — | 13 jul 2026 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData). |
| CVE-2026-51538 | Crítica (9.1) | 0.52% | — | 13 jul 2026 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies… |
| CVE-2026-51537 | Crítica (9.1) | 0.65% | — | 13 jul 2026 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame… |
| CVE-2026-51536 | Crítica (9.1) | 0.63% | — | 13 jul 2026 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as… |
| CVE-2022-43606 | Alta (7.5) | 8.0% | — | 16 mar 2023 | A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to… |
| CVE-2022-43605 | Crítica (9.8) | 14% | — | 16 mar 2023 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out… |
| CVE-2022-43604 | Crítica (9.8) | 14% | — | 16 mar 2023 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an… |
| CVE-2022-32434 | Alta (7.8) | 0.83% | — | 15 jul 2022 | EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSIX/OpENer+0x56073d. |
| CVE-2021-27500 | Alta (7.5) | 1.3% | — | 12 may 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition. |
| CVE-2021-27498 | Alta (7.5) | 1.3% | — | 12 may 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition. |
| CVE-2021-27482 | Alta (7.5) | 1.3% | — | 12 may 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data. |
| CVE-2021-27478 | Alta (7.5) | 1.1% | — | 12 may 2022 | A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition. |
| CVE-2021-21777 | Crítica (10) | 1.7% | — | 17 jun 2021 | An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds… |
| CVE-2020-13556 | Crítica (9.8) | 4.7% | — | 11 dic 2020 | An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code… |
| CVE-2020-13530 | Alta (7.5) | 2.1% | — | 11 dic 2020 | A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.