CVE-2026-16225

Summary

A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bounds write. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Affected Software

VendorProductVersion RangeStatus
davenardellasnap71.4.0affected
davenardellasnap71.4.1affected
davenardellasnap71.4.2affected
davenardellasnap71.4.3affected

Weaknesses

  • CWE-787: Out-of-bounds Write
  • CWE-119: Memory Corruption

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References