CVE-2026-82357

high

Description

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.

References

https://www.cve.org/CVERecord?id=CVE-2026-82357

https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf

https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json

https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91022

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

CVSS v4

Base Score: 7.1

Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00287