PT-2021-6748 · Unified Automation · Unified Automation .Net Based Opc Ua Client/Server Sdk Bundle
Eran Jacob
·
Published
2021-02-19
·
Updated
2023-10-15
·
CVE-2021-27434
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Unified Automation .NET based OPC UA Client/Server SDK Bundle versions V3.0.7 and prior
Description
The issue is related to an uncontrolled recursion that may allow an attacker to trigger a stack overflow. It is also associated with information disclosure, which could enable a remote attacker to disclose protected information.
Recommendations
For versions V3.0.7 and prior, update to a version later than V3.0.7 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unified Automation .Net Based Opc Ua Client/Server Sdk Bundle