Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-32170

Опубликовано: 03 мая 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. User interaction is required to exploit this vulnerability in that the target must choose to accept a client certificate.

The specific flaw exists within the processing of client certificates. The issue results from the lack of proper validation of certificate data. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20494.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:unified-automation:uagateway:*:*:*:*:*:*:*:*
Версия до 1.5.13.487 (исключая)

EPSS

Процентиль: 70%
0.00622
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
github
почти 2 года назад

Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. User interaction is required to exploit this vulnerability in that the target must choose to accept a client certificate. The specific flaw exists within the processing of client certificates. The issue results from the lack of proper validation of certificate data. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20494.

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость программного сетевого средства для миграции серверов UaGateway, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 70%
0.00622
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20