Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2021-45117
Disclosure Date: March 21, 2022 (last updated October 07, 2023)
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2021-40142
Disclosure Date: August 27, 2021 (last updated November 28, 2024)
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
0
Attacker Value
Unknown
CVE-2021-27432
Disclosure Date: May 20, 2021 (last updated November 28, 2024)
OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
0
Attacker Value
Unknown
CVE-2020-29457
Disclosure Date: February 16, 2021 (last updated November 28, 2024)
A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.
0
Attacker Value
Unknown
CVE-2020-8867
Disclosure Date: April 22, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application. Was ZDI-CAN-10295.
0
Attacker Value
Unknown
CVE-2019-19135
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
0
Attacker Value
Unknown
CVE-2018-12087
Disclosure Date: October 03, 2018 (last updated November 27, 2024)
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
0
Attacker Value
Unknown
CVE-2018-12585
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
0
Attacker Value
Unknown
CVE-2018-12086
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
0
Attacker Value
Unknown
CVE-2017-12070
Disclosure Date: June 14, 2018 (last updated November 26, 2024)
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
0