Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53xf-f462-gx5v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.

EPSS

Процентиль: 59%
0.00377
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость серверов TwinCAT OPC UA Server, IPC Diagnostics UA Server, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 59%
0.00377
Низкий

Дефекты

CWE-20