PT-2022-16658 · Asneg · Opcuastack

Sharon Brizinov

+2

·

Published

2022-08-23

·

Updated

2022-08-25

·

CVE-2022-24381

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions asneg/opcuastack versions (affected versions not specified)
Description The issue is related to a Denial of Service (DoS) due to a missing limitation on the number of received chunks per single session or in total for all concurrent sessions. An attacker can exploit this by sending an unlimited number of huge chunks (e.g., 2GB each) without sending the Final closing chunk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2022-24381

Affected Products

Opcuastack