PT-2022-17596 · Opcua · Opcua
Sharon Brizinov
+2
·
Published
2022-08-24
·
Updated
2022-08-26
·
CVE-2022-25903
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
opcua versions 0.0.0 through 0.11.0
Description
The issue allows for Denial of Service (DoS) via the ExtensionObjects and Variants objects. This occurs because the package allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed.
Recommendations
For versions 0.0.0 through 0.11.0, consider disabling the use of ExtensionObjects and Variants objects until a patch is available to prevent unlimited nesting levels and potential stack overflows.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opcua