HIGH7.5
GHSA-vpf7-r2fv-75m9
Uncontrolled Resource Consumption in OPC UA .NET Standard Reference Server
Quick fix
GHSA-vpf7-r2fv-75m9 — OPCFoundation.NetStandard.Opc.Ua.Server: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Server --version 1.4.371.86Details
This security update resolves a vulnerability in the OPC UA .NET Standard Reference Server that allows remote attackers to send malicious requests that consume all memory available to the server.
https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2023-27321.pdf
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Server
Introduced in:
0Fixed in: 1.4.371.86Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Server --version 1.4.371.86References
- https://github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-vpf7-r2fv-75m9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-27321[ADVISORY]
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2023-27321.pdf[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[PACKAGE]
- https://www.zerodayinitiative.com/advisories/ZDI-23-548[WEB]