OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538
ID: 033d4be3-35d8-5b1f-8ba9-54b19d245b5d
STIX ID: report--033d4be3-35d8-5b1f-8ba9-54b19d245b5d
Feed Name: CosmicBytez Labs
**CVE-2026-51538 — OpENer 2.3.0 incorrect access control:** OpENer fails to verify session ownership when processing EtherNet/IP encapsulation commands (session_handle existence is checked but not tied to the originating TCP connection), allowing unauthenticated network attackers to hijack or terminate sessions on TCP/44818; the flaw is rated CVSS 9.1 and can cause DoS and unauthorized session control in industrial environments, with recommended mitigations including vendor patches, network segmentation, CIP Security, and OT-aware monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
