PT-2022-19886 · Unknown · Opc Ua .Net Standard Stack

Published

2022-06-16

·

Updated

2022-06-27

·

CVE-2022-29864

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OPC UA .NET Standard Stack version 1.04.368
Description The issue allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption, potentially leading to a denial-of-service. This can be achieved by sending a large number of message chunks, causing the server to trigger an out of memory exception.
Recommendations For OPC UA .NET Standard Stack version 1.04.368, consider implementing measures to limit the number of messages that can be sent to the server within a certain timeframe to prevent Uncontrolled Resource Consumption. As a temporary workaround, consider restricting access to the server or implementing rate limiting on incoming messages until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29864
GHSA-VHFW-V69P-CRCW
ZDI-22-854

Affected Products

Opc Ua .Net Standard Stack