The Opener Project maintains a focused, specialized product that occupies a prominent place in the vulnerability landscape relative to its size, with its exposure concentrated in memory-safety and type-handling weaknesses. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the low-level nature of the buffer manipulation, pointer dereferencing, and numeric conversion issues that recur across its disclosures. Defenders should treat updates for this product as high-priority given the severity tendency; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opener Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43605CRITICAL An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted | Mar 16, 2023 | 9.8 | 37 | NO | NO |
CVE-2022-43604CRITICAL An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted | Mar 16, 2023 | 9.8 | 35 | NO | NO |
CVE-2021-21777CRITICAL An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted networ | Jun 17, 2021 | 10.0 | 32 | NO | NO |
CVE-2022-32434HIGH EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSIX/OpENer+0x56073d. | Jul 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-27500HIGH A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition. | May 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-27498HIGH A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition. | May 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-13556CRITICAL An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of netw | Dec 11, 2020 | 9.8 | 25 | NO | NO |
CVE-2021-27482HIGH A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data. | May 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-27478HIGH A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition. | May 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-13530HIGH A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network request | Dec 11, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opener Project.
Media articles that mention a CVE ID that affects a product developed by Opener Project — matched by CVE ID, not by vendor name.