o6 Automation open62541
Plan PatchCVSS 8.8ICS-CERT ICSA-26-211-08Jul 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
open62541 versions 1.3.0–1.3.17, 1.4.0–1.4.16, 1.5.0–1.5.4, and the master branch contain integer overflow (CWE-190, CWE-191) and use-after-free (CWE-416) vulnerabilities. An authenticated attacker can exploit these flaws to disclose sensitive information, cause denial of service by crashing the OPC UA server, or potentially execute arbitrary code on the host system. The vulnerabilities are triggered by specially crafted OPC UA protocol messages sent by a user with valid credentials.
What this means
What could happen
An attacker with login credentials to an OPC UA server running vulnerable open62541 could trigger integer overflow or use-after-free flaws to read sensitive data, crash the server, or potentially run arbitrary code on the system hosting the OPC UA service.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using open62541-based OPC UA servers for SCADA communications, remote terminal units (RTUs), programmable logic controllers (PLCs), or engineering workstations. This includes any system running open62541 versions 1.3 through 1.5 on Windows or Linux as part of industrial automation or process control systems.
How it could be exploited
An attacker must have valid OPC UA user credentials to authenticate to the server. Once authenticated, the attacker sends specially crafted OPC UA messages that trigger integer overflow (CWE-190/191) or use-after-free (CWE-416) conditions in the open62541 stack processing. This could result in information disclosure, denial of service, or code execution depending on the memory layout and how the vulnerability manifests during message processing.
Prerequisites
- Valid OPC UA user credentials for the server
- Network access to the OPC UA port (typically 4840/TCP)
- open62541 version 1.3.0–1.3.17, 1.4.0–1.4.16, 1.5.0–1.5.4, or master branch in use
Remotely exploitableRequires valid user credentialsLow-to-moderate attack complexityNo patch publicly available yet (vendor working on fixes)Affects OPC UA communication stacks central to industrial automation
Exploitability
Some exploitation risk — EPSS score 1.5%
Affected products (4)
4 pending
ProductAffected VersionsFix Status
open62541 on Windows and Linux: >=from_1.3.0|<=1.3.17≥ from 1.3.0|≤ 1.3.17No fix yet
open62541 on Windows and Linux: >=from_1.4.0|<=1.4.16≥ from 1.4.0|≤ 1.4.16No fix yet
open62541 on Windows and Linux: >=from_1.5.0|<=1.5.4≥ from 1.5.0|≤ 1.5.4No fix yet
open62541 on Windows and Linux: mastermasterNo fix yet
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDRestrict network access to the OPC UA port (default 4840/TCP) to only authorized engineering and SCADA networks; deny access from untrusted or external networks
HARDENINGReview and enforce OPC UA user credentials; disable or remove unnecessary user accounts with access to the OPC UA server
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate open62541 to the fixed version released after versions 1.3.17, 1.4.16, or 1.5.4 by applying the patches from the provided GitHub pull requests (8235, 8236, 8237, 8238) or contacting o6 Automation for a patched release
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate OPC UA servers from general corporate networks and the internet
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/dc430592-66f1-497b-aae3-c9833f896d5eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.