QID 981817

QID 981817: Dotnet (nuget) Security Update for OPCFoundation.NetStandard.Opc.Ua (GHSA-9q94-v7ch-mxqw)

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application. Was ZDI-CAN-10295.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-9q94-v7ch-mxqw for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981817

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9q94-v7ch-mxqw OPCFoundation.NetStandard.Opc.Ua URL Logo github.com/advisories/GHSA-9q94-v7ch-mxqw