02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: icscerto6 Automation open62541 Integer Overflow or Wraparound
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
- SSVC decision
- ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
- AutomatableyesAn attacker can reliably automate reconnaissance through exploitation, so this scales.
- Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 0.43% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 36.0% of scored records. A rank, not a probability.
- NVD base score
- 8.7 (CVSS v4.0), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- NVD analysis status
- Awaiting Analysis. NVD last modified this record on 2026-09-03.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.2
- Published
- 2026-07-30 21:47Z1 MO AGO
- Last updated
- 2026-08-25 14:22Z10 DAYS AGO
- Reserved
- 2026-07-27
- Assigning CNA
- icscert
- Record state
- PUBLISHED
- Severity
- High (CVSS 8.7)
- CNA CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- Weaknesses
- CWE-190Integer Overflow or WraparoundBase
- Data version
- 5.2
- Document digest
- 6786a116e066beb99e75473a9495c70b645380bae03266ef81eae3ff62994f8b
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
o6 Automationopen625411.3.0 to 1.3.17, 1.4.0 to 1.4.16, 1.5.0 to 1.5.4, masterWindows, Linux SRC: CNA
o6 Automation has prepared mitigations and fixes to address these
issues and recommends that users update to the newest version. The new
version can be obtained by contacting o6 Automation https://www.o6-automation.com/contact
or by downloading from the
following locations:
https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f
https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60
https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e
https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df
For more information, see open62541
Security Advisories SA-2026-0012, SA-2026-0014, and SA-2026-0015 or
contact o6 Automation: https://www.o6-automation.com/contact