logo

OpENer EtherNet/IP Session Access Control Bypass — CVE-2026-51538

ID: 033d4be3-35d8-5b1f-8ba9-54b19d245b5d

STIX ID: report--033d4be3-35d8-5b1f-8ba9-54b19d245b5d

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

...
...

**CVE-2026-51538 — OpENer 2.3.0 incorrect access control:** OpENer fails to verify session ownership when processing EtherNet/IP encapsulation commands (session_handle existence is checked but not tied to the originating TCP connection), allowing unauthenticated network attackers to hijack or terminate sessions on TCP/44818; the flaw is rated CVSS 9.1 and can cause DoS and unauthorized session control in industrial environments, with recommended mitigations including vendor patches, network segmentation, CIP Security, and OT-aware monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.