Sceawere
Vulnerability Detail
CVE-2026-82358UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
C-Open SDO Write Protection Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1d ago
- Vendor
- RT-Labs AB
- Product
- C-Open
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-01T20:17:32.540Z",
"pubdate": "2026-10-01T20:17:32.540Z",
"executiveSummary": "The RT-Labs AB C-Open CANopen library contains a critical vulnerability in the SDO (Service Data Object) server implementation that facilitates the unauthorized modification of read-only Object Dictionary (OD) entries.\nThis vulnerability is classified as a write protection bypass, arising from insufficient validation of write permissions during the processing of download-segment frames.\nThe flaw affects the 'src/co_sdo_server.c' component within versions prior to 1.1.1.\nAn unauthenticated attacker with access to the CAN bus can exploit this by manipulating the SDO state machine to overwrite sensitive memory locations, even when those entries are explicitly defined as read-only in the Object Dictionary.\nGiven that the CANopen protocol lacks inherent authentication, this vulnerability enables any node on the bus to execute unauthorized write operations, potentially compromising the integrity of device configurations, operational parameters, or safety-critical logic residing in the memory space mapped to the Object Dictionary.\nThe risk is high, as it allows for persistent or transient alteration of embedded system behavior without requiring elevated privileges.",
"technicalDetails": "The vulnerability resides in the 'src/co_sdo_server.c' file within the SDO server implementation of the C-Open CANopen library. The root cause is a failure in the SDO download-segment handler to enforce strict write-access validation and state session verification for incoming CAN frames.\nIn the CANopen architecture, the SDO protocol is used for accessing entries in the Object Dictionary (OD). Normally, the OD maps indices to specific memory addresses, with associated attributes defining whether an entry is read-only, write-only, or read-write. The implementation fails to properly validate these attributes when processing download-segment requests.\nThe exploitation flow is a two-step process initiated by an unauthenticated attacker on the CAN bus:\n1. Initiation: The attacker initiates an SDO upload request for an index that points to a read-only object. During this process, the SDO server sets a internal data pointer to the memory location of this read-only object to prepare for the 'upload' sequence.\n2. Exploitation: Instead of completing the upload, the attacker sends specially crafted download-segment frames. The vulnerable implementation fails to verify whether a valid download session was legitimately initiated or if the current state machine context permits write operations to the target pointer. Because the internal data pointer was already set by the initial upload request to the desired memory location, the download-segment handler proceeds to write the payload contained in the frames directly into the target memory address associated with the read-only OD entry.\nThe core of the issue is the lack of a session-tracking mechanism that ties the download-segment handler to an authorized 'download' session. By confusing the state machine through the combination of an upload-trigger and a subsequent download-segment frame, the attacker effectively bypasses the object dictionary's protection logic.\nThe impact is significant because it permits an attacker to perform unauthorized writes to any memory location mapped within the Object Dictionary, regardless of the configured access permissions. This can lead to the corruption of device parameters, alteration of control flow, or the modification of safety parameters, depending on what data is stored in the affected OD index. Because the vulnerability is exploitable by any node on the CAN bus and requires no authentication, any entity capable of sending CAN messages can subvert the system's security posture."
}