Описание
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
A flaw was found in open62541. A remote attacker can exploit an incomplete validation flaw in the server-side AddReferences implementation. By sending a specially crafted request, an attacker can cause a null pointer dereference, leading to a Denial of Service (DoS) condition. This can make the server unavailable to legitimate users.
Отчет
This Important denial of service flaw in open62541 allows a remote, unauthenticated attacker to crash the server. The vulnerability arises from insufficient validation of non-local ExpandedNodeId targets within the AddReferences implementation, which can lead to a NULL pointer dereference and service unavailability.
Меры по смягчению последствий
Restrict who can invoke NodeManagement / AddReferences (trusted clients only) and limit OPC UA server network exposure.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
In open62541 v1.5.5, the server-side AddReferences implementation cont ...
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
EPSS
7.5 High
CVSS3