CVE-2026-22885 PUBLISHED

EnOcean SmartServer IoT Out-of-bounds Read

Assigner: icscert
Reserved: 12.02.2026 Published: 20.02.2026 Updated: 20.02.2026

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 3.7

Product Status

Vendor EnOcean Edge Inc
Product SmartServer IoT
Versions Default: unaffected
  • affected from 0 to 4.60.009 (incl.)
  • Version 4.60.023 is unaffected

Workarounds

For additional mitigations and workarounds, refer to EnOcean's hardening guide at https://enoceanwiki.atlassian.net/wiki/spaces/IEC/pages/288063529/Enhancing+Security .

Solutions

EnOcean recommends users update the SmartServer platform software to SmartServer 4.6 Update 2 (v4.60.023) or a later release at https://enoceanwiki.atlassian.net/wiki/spaces/DrftSSIoT/pages/1475410/SmartServer+IoT+Release+Notes#... https://enoceanwiki.atlassian.net/wiki/spaces/DrftSSIoT/pages/1475410/SmartServer+IoT+Release+Notes#Current-Stable-Release .

Credits

  • Amir Zaltzman of Claroty Team82 reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-125 CWE