CVE-2026-15105: Out-of-bounds Write in davenardella snap7
A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes out-of-bounds write. The attack requires access to the local network. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
AI Analysis
Technical Summary
This vulnerability in davenardella snap7 (versions up to 1.4.3) involves an out-of-bounds write in the TS7Worker::PerformFunctionRead function located in src/core/s7_server.cpp. The flaw allows an attacker with local network access to manipulate the ReadVar Request Handler, potentially causing memory corruption. Although an exploit has been published, the vendor has not yet responded or issued a fix. The CVSS 4.0 vector indicates the attack requires adjacent network access with low complexity and no privileges or user interaction needed, but with low to limited impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation can lead to out-of-bounds memory writes, which may cause application instability or crashes and potentially enable further exploitation such as code execution or denial of service. The attack requires local network access, limiting remote exploitation. The medium CVSS score reflects moderate risk due to these factors.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict local network access to the affected snap7 service to trusted users only and consider applying network-level controls to limit exposure.
CVE-2026-15105: Out-of-bounds Write in davenardella snap7
Description
A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes out-of-bounds write. The attack requires access to the local network. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS v4.0
Score 5.3medium
Affected software
pkg:deb/ubuntu/[email protected]+dfsg-1?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-1build1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in davenardella snap7 (versions up to 1.4.3) involves an out-of-bounds write in the TS7Worker::PerformFunctionRead function located in src/core/s7_server.cpp. The flaw allows an attacker with local network access to manipulate the ReadVar Request Handler, potentially causing memory corruption. Although an exploit has been published, the vendor has not yet responded or issued a fix. The CVSS 4.0 vector indicates the attack requires adjacent network access with low complexity and no privileges or user interaction needed, but with low to limited impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation can lead to out-of-bounds memory writes, which may cause application instability or crashes and potentially enable further exploitation such as code execution or denial of service. The attack requires local network access, limiting remote exploitation. The medium CVSS score reflects moderate risk due to these factors.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict local network access to the affected snap7 service to trusted users only and consider applying network-level controls to limit exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-15105
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a58b4f568715ace43db1ff8
Added to database: 07/16/2026, 10:39:49 UTC
Last enriched: 08/01/2026, 22:15:39 UTC
Last updated: 09/14/2026, 10:01:29 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.