PT-2022-4447 · Unknown · Node-Opcua

Sharon Brizinov

+2

·

Published

2022-08-24

·

Updated

2022-08-26

·

CVE-2022-24375

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions node-opcua versions prior to 2.74.0
Description The issue is related to a Denial of Service (DoS) condition that can be triggered by bypassing limitations for excessive memory consumption. This can be achieved by sending multiple CloseSession requests with the deleteSubscription parameter set to False. The vulnerability is associated with incorrect cleanup or release of resources, which can be exploited by a remote attacker to cause a service disruption.
Recommendations For versions prior to 2.74.0, update to version 2.74.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CloseSession request or setting the deleteSubscription parameter to True to minimize the risk of exploitation.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2022-05312
CVE-2022-24375
GHSA-VH4F-FGPP-X8X2

Affected Products

Node-Opcua