PT-2021-6748 · Unified Automation · Unified Automation .Net Based Opc Ua Client/Server Sdk Bundle

Eran Jacob

·

Published

2021-02-19

·

Updated

2023-10-15

·

CVE-2021-27434

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Unified Automation .NET based OPC UA Client/Server SDK Bundle versions V3.0.7 and prior
Description The issue is related to an uncontrolled recursion that may allow an attacker to trigger a stack overflow. It is also associated with information disclosure, which could enable a remote attacker to disclose protected information.
Recommendations For versions V3.0.7 and prior, update to a version later than V3.0.7 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

BDU:2022-02137
CVE-2021-27434

Affected Products

Unified Automation .Net Based Opc Ua Client/Server Sdk Bundle