Integer Overflow Vulnerability in open62541's UA_Variant Array Dimensions
CVE-2026-65423
8.7HIGH
What is CVE-2026-65423?
An integer overflow vulnerability has been identified in the UA_Variant array dimensions computation within open62541. This flaw could potentially enable a remote attacker to perform an out-of-bounds write, which may lead to unauthorized access or manipulation of system memory. It is crucial for users of open62541 to assess their installations for this vulnerability and apply necessary mitigations to safeguard their systems.
Affected Version(s)
open62541 Windows 1.3.0 <= 1.3.17
open62541 Windows 1.4.0 <= 1.4.16
open62541 Windows 1.5.0 <= 1.5.4
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abhinav Agarwal reported this vulnerability to CISA.
