PT-2024-20726 · Softing · Softing Uatoolkit Embedded
Published
2024-04-02
·
Updated
2024-04-03
·
CVE-2024-25075
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Softing uaToolkit Embedded versions prior to 1.41.1
Description
An issue was discovered in Softing uaToolkit Embedded. When a subscription with a very low
MaxNotificationPerPublish parameter is created, a publish response is mishandled, leading to memory consumption. When that happens often enough, the device will be out of memory, i.e., a denial of service.Recommendations
For versions prior to 1.41.1, update to version 1.41.1 or later to resolve the issue. As a temporary workaround, consider restricting the creation of subscriptions with very low
MaxNotificationPerPublish parameters to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Softing Uatoolkit Embedded