CVE-2026-67871 Details
Description
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
A buffer overflow vulnerability has been identified in Systerel S2OPC version 1.7.3. This vulnerability allows a remote attacker to cause a denial-of-service by exploiting a type confusion in the AddNodes service. When Node Management is enabled, the server incorrectly accepts generic node attributes for variable nodes, leading to a heap-buffer-overflow error. This issue can be reproduced using a crafted AddNodes request that bypasses type validation, causing the server to crash.
Users can update to Systerel S2OPC version 1.7.4, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.com/systerel/S2OPC/-/work_items/1787 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/address_space/internal/sopc_node_mgt_helper_internal.c | [email protected] | Source CodeVendor |
| https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/address_space_bs.c | [email protected] | Source CodeVendor |
| https://github.com/systerel/S2OPC/blob/S2OPC_Toolkit_1.7.3/tests/ClientServer/CMakeLists.txt | [email protected] | Source CodeVendor |
| https://gitlab.com/systerel/S2OPC/-/work_items/1787 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Systerel S2OPC | 1.7.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion