Vulnerability vector:
Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Severity (CVSSv4.0): 7.1 (High)
Description:
The vulnerability was identified in Centum VP, versions R1.07.00 or earlier.
The discovered vulnerability allows an attacker to to perform an out‑of‑bounds memory read in the command handler, because the code fails to validate integer overflow and does not check that length fields of externally‑controlled data match the actual data size.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: 13.02.2026
Recommendations:
- Update to version R1.08.00 or higher
Additional information:
Researcher: Dmitry Sklyar (Positive Technologies)