PT-2021-7242 · Opc Foundation · Opc Foundation Local Discovery Server

Published

2021-08-25

·

Updated

2022-09-03

·

CVE-2021-40142

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OPC Foundation Local Discovery Server (LDS) versions prior to 1.04.402.463
Description The issue is related to a denial of service (DoS) that can be caused by remote attackers sending carefully crafted messages, leading to access of a memory location after the end of a buffer. This can result in a service disruption. The vulnerability is associated with a buffer overflow operation in the memory.
Recommendations For versions prior to 1.04.402.463, update to version 1.04.402.463 or later to resolve the issue. As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation.

Fix

Buffer Overflow

Access of Memory Location After End of Buffer

Weakness Enumeration

Related Identifiers

BDU:2022-04114
CVE-2021-40142

Affected Products

Opc Foundation Local Discovery Server