Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3jq-gg7x-47cq

Опубликовано: 01 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It does not implement a check to see if such an object is recursively defined, so an attack could send a maliciously created message that the decoder would try to decode until the stack overflowed and the device crashed.

PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It does not implement a check to see if such an object is recursively defined, so an attack could send a maliciously created message that the decoder would try to decode until the stack overflowed and the device crashed.

EPSS

Процентиль: 25%
0.00086
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It does not implement a check to see if such an object is recursively defined, so an attack could send a maliciously created message that the decoder would try to decode until the stack overflowed and the device crashed.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость реализации протокола OPC UA программного обеспечения OPC-сервера KEPServerEX, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 25%
0.00086
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-787