PT-2022-16588 · Freeopcua · Freeopcua

Sharon Brizinov

+2

·

Published

2022-08-23

·

Updated

2026-03-03

·

CVE-2022-24298

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions freeopcua/freeopcua versions all
Description The issue allows for Denial of Service (DoS) by bypassing limitations for excessive memory consumption. This is achieved by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
Recommendations For all versions, consider restricting access to the CloseSession request or implementing measures to limit excessive memory consumption as a temporary workaround until a patch is available.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2022-24298

Affected Products

Freeopcua