← Vulnerability feed

Vulnerability record · CVE-2022-43604 · published 16 March 2023

CVE-2022-43604: Opener project opener out-of-bounds write vulnerability

Opener Project · Opener

An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

9.8 CVSS 3.1 Critical EPSS 14% · top 3.5% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-43604 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-21777Opener project opener out-of-bounds read vulnerabilityAn information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73…EPSS 1.7%9.8CVE-2026-51540Opener project opener vulnerabilityOpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing …EPSS 0.57%9.8CVE-2022-43605Opener project opener out-of-bounds write vulnerabilityAn out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commi…EPSS 14%9.8CVE-2020-13556Opener project opener out-of-bounds write vulnerabilityAn out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A s…EPSS 4.7%9.1CVE-2026-51536Opener project opener integer overflow vulnerabilityIn OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed…EPSS 0.63%9.1CVE-2026-51537Opener project opener out-of-bounds read vulnerabilityEIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing sh…EPSS 0.65%9.1CVE-2026-51538Opener project opener improper access control vulnerabilityEIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When th…EPSS 0.52%9.1CVE-2026-51541Opener project opener out-of-bounds read vulnerabilityOpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath si…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2022-43604), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.