Open Vehicle Monitoring System 3 Buffer Overflow Vulnerability in CANswitch Log Parsing

Vulnerability

A buffer overflow vulnerability has been identified in Open Vehicle Monitoring System 3 (OVMS3) version 3.3.005. The issue arises in the CANswitch log format parser, where the parser fails to properly validate the Data Length Code (DLC) of incoming CANswitch frames. This lack of validation allows remote attackers to send crafted CANswitch frames that can lead to a denial-of-service condition or potentially execute arbitrary code.

Impact

Exploitation of this vulnerability causes a stack buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition.

Added: May 1, 2026, 5:21 PM
Updated: May 1, 2026, 5:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.1
remediation
0.0
relevance
7.2
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.