Out-of-Bounds Read Vulnerability in Systerel S2OPC Product
CVE-2026-82618

5.3MEDIUM

Key Information:

Vendor

Systerel

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82618?

A security vulnerability has been identified in Systerel's S2OPC, specifically in the String Array Range Writing component. The issue lies in the set_range_matrix_on_string_array function, where improper handling of data can lead to an out-of-bounds read scenario. This vulnerability can be exploited remotely by attackers, potentially allowing them unauthorized access to sensitive information. Despite awareness of the problem through prior reporting, no response or fix has been implemented by the project team to date.

Affected Version(s)

S2OPC 1.7.0

S2OPC 1.7.1

S2OPC 1.7.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Carnegie (VulDB User)
VulDB CNA Team
.