PT-2023-3423 · Unified Automation · Uagateway

Noam Moshe

+3

·

Published

2023-05-31

·

Updated

2025-08-08

·

CVE-2023-32172

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Unified Automation UaGateway (affected versions not specified)
Description The issue is related to a use-after-free condition, which can be exploited by remote attackers to create a denial-of-service condition on affected installations. The specific flaw exists within the implementation of the ImportXML function, where the lack of validation of an object's existence prior to performing operations on it can be leveraged by an attacker. Authentication is required to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2023-03601
CVE-2023-32172
ZDI-23-777

Affected Products

Uagateway