PT-2022-4441 · Unknown · Node-Opcua

·

CVE-2022-25231

·

Published

2022-08-22

·

Updated

2022-08-26

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions node-opcua versions prior to 2.74.0
Description The issue is related to a Denial of Service (DoS) condition that can be triggered by sending a specifically crafted OPC UA message with a special OPC UA NodeID. This occurs when the requested memory allocation exceeds the v8's memory limit, leading to uncontrolled resource consumption. The exploitation of this issue may allow a remote attacker to cause a service disruption.
Recommendations For node-opcua versions prior to 2.74.0, update to version 2.74.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the OPC UA NodeID to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05305
CVE-2022-25231
GHSA-QPGC-XH7J-52Q8

Affected Products

Node-Opcua