PT-2022-4441 · Unknown · Node-Opcua

Sharon Brizinov

+2

·

Published

2022-08-22

·

Updated

2022-08-26

·

CVE-2022-25231

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions node-opcua versions prior to 2.74.0
Description The issue is related to a Denial of Service (DoS) condition that can be triggered by sending a specifically crafted OPC UA message with a special OPC UA NodeID. This occurs when the requested memory allocation exceeds the v8's memory limit, leading to uncontrolled resource consumption. The exploitation of this issue may allow a remote attacker to cause a service disruption.
Recommendations For node-opcua versions prior to 2.74.0, update to version 2.74.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the OPC UA NodeID to minimize the risk of exploitation.

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2022-05305
CVE-2022-25231
GHSA-QPGC-XH7J-52Q8

Affected Products

Node-Opcua