HIGH7.5
GHSA-5q2v-6j86-5h9v
Security Update for the OPC UA .NET Standard Stack
Quick fix
GHSA-5q2v-6j86-5h9v — OPCFoundation.NetStandard.Opc.Ua.Core: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58Details
A vulnerability was discovered in OPC UA .NET Standard Stack that allows a malicious client or server to cause a peer to hang with a carefully crafted message sent during secure channel creation.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Core
Introduced in:
0Fixed in: 1.4.368.58Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58References
- https://github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-5q2v-6j86-5h9v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-29862[ADVISORY]
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-29862.pdf[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[PACKAGE]