Описание
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
A flaw was found in open62541. A remote attacker can exploit a buffer overflow vulnerability within the Service_Call function. This vulnerability arises from improper validation of input arguments against runtime-resolved InputArguments metadata, which can lead to a denial of service (DoS).
Отчет
This Important flaw in open62541 allows a remote, unauthenticated attacker to trigger a denial of service. The vulnerability stems from insufficient validation of input arguments within the Service_Call function, which can lead to a buffer overflow and subsequent service unavailability.
Меры по смягчению последствий
No practical workaround identified beyond restricting NodeManagement / method-metadata changes to trusted principals and limiting network exposure of the OPC UA server.
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote atta ...
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
7.5 High
CVSS3