Systerel vulnerabilities
5 CVEs tracked
Systerel appears in our reports exclusively in the context of critical vulnerabilities in its S2OPC product. All reports focus on Denial of Service (DoS) flaws via Buffer Overflow vulnerabilities in versions up to 1.7.3, exploitable by a remote attacker. Key affected components include the DeleteMonitoredItems request handler, PublishResponse processing, AddNodes function, and event monitored-item queue resizing. Defenders should immediately upgrade S2OPC from version 1.7.3, monitor OPC UA traffic, and consider network-level restrictions addressing these CVEs: CVE-2026-18790, CVE-2026-67866, CVE-2026-67867, CVE-2026-67871, and CVE-2026-67872.
Azərbaycanca: Systerel, hesabatlarımızda yalnız S2OPC məhsulu ilə bağlı kritik zəifliklər kontekstində görünür. Bütün xəbərlər 1.7.3 versiyasına qədər olan məhsulda aşkarlanmış və uzaqdan hücum edən şəxsə xidmət əngəli (Denial of Service) yaratmağa imkan verən Buffer Overflow zəifliklərinə fokuslanıb. Xüsusilə DeleteMonitoredItems sorğu idarəedicisi, PublishResponse emalı, AddNodes funksiyası və event monitorinq növbəsi ölçüsünün dəyişdirilməsi kimi komponentlər hədəf alınıb. Müdafiəçilər S2OPC versiyalarını dərhal 1.7.3-dən yuxarı yeniləməli, OPC UA trafikini izləməli və bu CVE-lərə (CVE-2026-18790, CVE-2026-67866, CVE-2026-67867, CVE-2026-67871, CVE-2026-67872) qarşı şəbəkə səviyyəsində məhdudiyyətləri nəzərdən keçirməlidir.
This vendor's CVEs5
This hub is built from skopnix's own reporting on Systerel: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.