PT-2026-83710 · Open62541 · Open62541
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
open62541 versions prior to 1.5.6
Description
A remote attack can trigger a use after free condition within the History Backend component. This occurs specifically in the
UA DataValue backend copyRange() function located in the plugins/historydata/ua history data backend memory.c file. Use after free is a memory corruption issue where a program continues to use a pointer after it has been freed, potentially leading to crashes or arbitrary code execution.Recommendations
Update open62541 to a version newer than 1.5.5.
As a temporary mitigation, restrict access to the History Backend component to minimize the risk of remote exploitation.
Exploit
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open62541