Denial of Service Vulnerability in open62541 by Remote Attackers
CVE-2026-63362
8.2HIGH
What is CVE-2026-63362?
An unsigned integer underflow vulnerability in the PubSub signature verification path of open62541 can be exploited by remote attackers. By sending specially crafted UDP packets, an attacker may trigger a denial of service condition, disrupting the operation of affected systems. It is essential for users of open62541 to apply the latest patches to mitigate this risk and ensure the integrity and availability of their services.
Affected Version(s)
open62541 Windows 1.3.0 <= 1.3.17
open62541 Windows 1.4.0 <= 1.4.16
open62541 Windows 1.5.0 <= 1.5.4
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abhinav Agarwal reported this vulnerability to CISA.
