Vulnerability Description
Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softing | Opc Ua C\+\+ Software Development Kit | >= 5.59.0, < 5.65.0 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-168-02Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-168-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-32994?
CVE-2021-32994 is a vulnerability with a CVSS score of 7.5 (HIGH). Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the sof...
How severe is CVE-2021-32994?
CVE-2021-32994 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32994?
Check the references section above for vendor advisories and patch information. Affected products include: Softing Opc Ua C\+\+ Software Development Kit.