Vulnerability Description
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opcfoundation | Ua .Net Standard Stack | < 1.4.368.58 |
Related Weaknesses (CWE)
References
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20PatchVendor Advisory
- https://opcfoundation.org/security/Vendor Advisory
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20PatchVendor Advisory
- https://opcfoundation.org/security/Vendor Advisory
FAQ
What is CVE-2022-29866?
CVE-2022-29866 is a vulnerability with a CVSS score of 7.5 (HIGH). OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
How severe is CVE-2022-29866?
CVE-2022-29866 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29866?
Check the references section above for vendor advisories and patch information. Affected products include: Opcfoundation Ua .Net Standard Stack.