Loading market data...
← Back to CVE feed

CVE-2026-51537

CRITICAL CVSS 9.1 View on NVD ↗

Description

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Published: Jul 13, 2026 22:16 UTC Modified: Jul 14, 2026 14:16 UTC