Sceawere

Vulnerability Detail

CVE-2026-82357UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

C-Open CANopen LSS NULL Dereference

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
RT-Labs AB
Product
C-Open
Attack Type
CWE-476 NULL Pointer Dereference
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-01T20:17:32.363Z",
  "pubdate": "2026-10-01T20:17:32.363Z",
  "executiveSummary": "The RT-Labs AB C-Open CANopen stack is susceptible to a NULL pointer dereference vulnerability triggered during the Layer Setting Services (LSS) protocol configuration phase.\nThe vulnerability arises when an identity object (specifically object 0x1018) is misconfigured by the user application, lacking mandatory subindexes required by the LSS implementation.\nAn unauthenticated, remote attacker with physical or logical access to the CAN bus can exploit this flaw by initiating LSS requests targeting the misconfigured object.\nSuccessful exploitation results in a device crash, leading to a Denial of Service (DoS) condition. This is particularly critical in industrial or automotive environments where CANopen nodes must maintain continuous availability.\nThe risk is primarily localized to the CAN network segment; however, any compromised node on the bus can act as a pivot to trigger this vulnerability.\nThe vulnerability is remediated in version 1.1.1 of the stack.",
  "technicalDetails": "The vulnerability is rooted in the improper handling of the CANopen Identity Object (0x1018) within the C-Open stack's LSS module. The CANopen LSS protocol provides mechanisms for dynamic assignment of Node-IDs and bit timing, which necessitates reading device identity parameters.\nSpecifically, the implementation assumes that the user application has fully populated object 0x1018 with all mandatory subindexes (Vendor ID, Product Code, Revision Number, and Serial Number). If the user application fails to define these subindexes, or defines them incompletely, the LSS implementation attempts to access a memory address derived from a pointer that has not been initialized or is null.\nThe attack flow proceeds as follows: First, the attacker gains access to the CAN bus. Second, the attacker transmits an LSS 'Identify Remote Slave' or 'Inquire' request frame. Third, the C-Open stack's internal LSS handler receives the request and attempts to validate the node identity by accessing object 0x1018. Fourth, due to the missing subindex definitions, the pointer intended to reference the object's data structure is NULL. Finally, the processor performs a dereference on this NULL pointer, triggering a hard fault or an exception that halts the device execution.\nThis vulnerability is classified as a NULL pointer dereference, which is a common memory safety issue in C-based embedded firmware. Because the LSS protocol is designed to operate regardless of the current device state, the exploitation does not require the attacker to have pre-existing privileges on the target node, only the ability to inject messages onto the CAN physical layer.\nThe scope of impact is limited to the local CAN network, but because CANopen is a broadcast-based protocol, the attack is simple to execute once bus access is achieved. No specialized firmware payload is required; merely sending the correctly formatted CAN frame is sufficient to induce the crash. Post-exploitation, the device will remain in a non-functional state until a hardware reset or power cycle is performed, directly impacting the availability of the control system.\nThis issue affects all versions of the C-Open stack prior to 1.1.1, where input validation logic for LSS object resolution was likely updated to verify pointer integrity before dereferencing."
}
CVE-2026-82357: C-Open CANopen LSS NULL Dereference (MEDIUM Severity, CVSS: 6.5) | Sceawere