← Terug naar overzicht

A memory corruption vulnerability has been identified in liftoff-sr CIPster at commit 1802525be27d33e19a9a83c163e331a1d13b1892. The flaw resides in the functions CipAttribute::GetAttrData and CipAttribute::SetAttrData within the ciptypes.h file under the Generic Attribute Logic component. An attacker can remotely exploit this vulnerability by manipulating input to trigger memory corruption. A public exploit is available, raising the risk of active exploitation in the wild. CIPster is an open-source implementation of the Common Industrial Protocol (CIP), commonly used in industrial and OT environments, making this a potentially critical infrastructure risk. A patch has been provided via commit e745d9d4a8ca3a13689066983a1269fe1e567674 on GitHub. Users are strongly advised to apply the patch immediately to mitigate exposure.

Affected products

  • liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892

Related CVE's

  • CVE-2026-76987

Categories

  • Critical Infrastructure
  • Network Infrastructure
  • Zero-Day Vulnerabilities