Vulnerability Description
OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply an attacker-controlled item_count value that is not consistently validated against the remaining data_length of the CPF slice
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/EIPStackGroup/OpENer
- https://github.com/EIPStackGroup/OpENer/issues/558
- https://github.com/EIPStackGroup/OpENer/issues/558
FAQ
What is CVE-2026-38719?
CVE-2026-38719 is a vulnerability with a CVSS score of 6.2 (MEDIUM). OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A cr...
How severe is CVE-2026-38719?
CVE-2026-38719 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-38719?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.