PT-2022-4450 · Opcua · Opcua
Sharon Brizinov
+2
·
Published
2022-08-23
·
Updated
2022-08-25
·
CVE-2022-25888
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
opcua versions 0.0.0 and later
Description
The issue is related to a Denial of Service (DoS) due to a missing limitation on the number of received chunks per single session or in total for all concurrent sessions. An attacker can exploit this by sending an unlimited number of huge chunks without sending the Final closing chunk, leading to uncontrolled resource consumption. This can allow a remote attacker to cause a service disruption.
Recommendations
For versions 0.0.0 and later, consider implementing a limitation on the number of received chunks per session or in total for all concurrent sessions to prevent uncontrolled resource consumption. As a temporary workaround, consider restricting the size of chunks that can be received or implementing rate limiting on incoming chunks to minimize the risk of exploitation.
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opcua