PT-2022-4441 · Unknown · Node-Opcua
Sharon Brizinov
+2
·
Published
2022-08-22
·
Updated
2022-08-26
·
CVE-2022-25231
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
node-opcua versions prior to 2.74.0
Description
The issue is related to a Denial of Service (DoS) condition that can be triggered by sending a specifically crafted OPC UA message with a special OPC UA NodeID. This occurs when the requested memory allocation exceeds the v8's memory limit, leading to uncontrolled resource consumption. The exploitation of this issue may allow a remote attacker to cause a service disruption.
Recommendations
For node-opcua versions prior to 2.74.0, update to version 2.74.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the OPC UA NodeID to minimize the risk of exploitation.
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node-Opcua