This vulnerability allows remote attackers to create a...
High severity
Unreviewed
Published
Mar 29, 2023
to the GitHub Advisory Database
•
Updated Apr 14, 2023
Description
Published by the National Vulnerability Database
Mar 29, 2023
Published to the GitHub Advisory Database
Mar 29, 2023
Last updated
Apr 14, 2023
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rollup]. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of certificates. A crafted certificate can force the server into an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-17203.
References