Sceawere

Vulnerability Detail

CVE-2026-82782UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CONPROSYS nano Series OOB Write

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Contec Co., Ltd.
Product
Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*
Attack Type
Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-14T07:17:19.943Z",
  "pubdate": "2026-09-14T07:17:19.943Z",
  "executiveSummary": "The CONPROSYS nano Series is susceptible to an out-of-bounds (OOB) write vulnerability, categorized as a critical memory corruption flaw. This vulnerability arises from improper input validation when processing incoming network requests.\nA remote, unauthenticated attacker can exploit this weakness by crafting a malicious payload specifically designed to trigger the out-of-bounds memory write operation. Successful exploitation of this flaw directly results in a denial-of-service (DoS) condition, rendering the affected device unresponsive or causing it to crash.\nThe risk is significant for industrial control environments relying on the CONPROSYS nano Series for automation, as the interruption of services can lead to operational downtime. The exploit requires no user interaction and can be performed over the network, making it a high-priority concern for network security administrators. There is no evidence currently suggesting that this vulnerability allows for remote code execution (RCE), but the memory corruption aspect poses potential risks to system stability that necessitate immediate protective measures.",
  "technicalDetails": "The vulnerability is rooted in an out-of-bounds write primitive present within the network packet processing logic of the CONPROSYS nano Series. The flaw manifests when the device fails to adequately perform bounds checking on the size of incoming data buffers relative to the allocated memory heap or stack destination during request handling.\nThe attack flow begins when an attacker sends a specially crafted request—likely violating the expected protocol specifications—to the listening network service on the target device. Because the application logic does not properly validate the length or structure of the incoming data, the routine responsible for processing the request writes the payload beyond the intended memory boundary. This overwrite operation corrupts adjacent memory structures, which may include function pointers, control flow data, or critical object metadata.\nThe immediate impact of this corruption is an unhandled exception or a segmentation fault, leading to the abrupt termination of the process or a kernel panic, effectively creating a denial-of-service condition. Because the vulnerable component resides in the network stack or the interface logic responsible for request parsing, the attack vector is fully remote and does not require prior authentication or privileged access. The attacker essentially forces the device into a state where it can no longer process legitimate traffic or maintain its primary control functions.\nIn scenarios where the memory corruption affects critical program counter registers or return addresses, the system may enter an unstable state before crashing, preventing recovery without a manual hardware reset or power cycle. The lack of robust sanitization during the packet ingestion phase is the primary technical failure, allowing arbitrary (though unstructured) data to be written into unauthorized memory segments. This flaw necessitates strict input validation and bounds checking, which were evidently missing or insufficient in the affected implementation."
}
CVE-2026-82782: CONPROSYS nano Series OOB Write (MEDIUM Severity, CVSS: 4.3) | Sceawere