Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ua .net Standard Stack MEDIUM 5.3
CVE-2024-42513

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HT…

Fix: 1.5.374.158+
Fix from $1,600 2025-02-10
Ua .net Standard Stack HIGH 8.6
CVE-2024-42512

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the depr…

Fix: 1.5.374.158+
Fix from $1,950 2025-02-10
Ua .netstandard HIGH 7.5
CVE-2023-27321

OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to c…

Fix: 1.4.371.86+
Fix from $1,950 2024-05-07
Ua .netstandard MEDIUM 5.3
CVE-2023-31048

The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.

Fix: 1.4.371.86+
Fix from $1,600 2023-12-12
Ua Java Legacy HIGH 7.5
CVE-2023-32787

The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that the…

Fix: 1.2.0 / 1.4.20+
Fix from $1,950 2023-05-15
Local Discovery Server HIGH 7.8
CVE-2022-44725

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to cr…

Fix: 1.04.405.479+
Fix from $1,950 2022-11-17
Ua .net Standard Stack HIGH 7.5
CVE-2022-33916

OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.

Patch available
Fix from $1,950 2022-08-23
Ua .net Standard Stack HIGH 7.5
CVE-2022-29863

OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Ua .net Standard Stack HIGH 7.5
CVE-2022-29864

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Reso…

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Ua .net Standard Stack HIGH 7.5
CVE-2022-29866

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontro…

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Ua .net Standard Stack HIGH 7.5
CVE-2022-29862

An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Ua .net Standard Stack HIGH 7.5
CVE-2022-29865

OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Ua Java HIGH 7.5
CVE-2022-30551

OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust a…

Patch available
Fix from $1,950 2022-05-20
Ua Nodeset MEDIUM 6.5
CVE-2021-45117

The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.

Fix: 1.05.01+
Fix from $1,600 2022-03-21
Local Discover Server HIGH 7.5
CVE-2021-40142

In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted…

Fix: 1.04.402.463 / 2022+
Fix from $1,950 2021-08-27
Ua .net Legacy HIGH 7.5
CVE-2021-27432

OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an a…

Fix: 1.4.365.48+
Fix from $1,950 2021-05-20
Unified Architecture .net Standard HIGH 7.5
CVE-2020-8867

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.…

Fix: after 1.04.358.30
Fix from $1,950 2020-04-22
Netstandard.opc.ua HIGH 7.4
CVE-2019-19135

In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua bef…

Fix: 1.4.359.31+
Fix from $1,950 2020-03-16
Ua .net Legacy MEDIUM 5.3
CVE-2018-12087

Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece o…

Mitigation only
Fix from $1,600 2018-10-03
Ua .net Legacy HIGH 8.2
CVE-2018-12585

An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

Fix: after 1.3.343
Fix from $1,950 2018-09-14
Ua .net Legacy HIGH 8.8
CVE-2017-12070

Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.

Mitigation only
Fix from $1,950 2018-06-14
Local Discovery Server HIGH 7.8
CVE-2017-11672

The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opcualds.ex…

Fix: 1.03.367+
Fix from $1,950 2018-06-13
Local Discovery Server MEDIUM 6.5
CVE-2017-17443

OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to trigger a…

Mitigation only
Fix from $1,600 2018-06-13
Ua .net Legacy MEDIUM 5.3
CVE-2018-7559

An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code b…

Fix: after 1.03.352.10
Fix from $1,600 2018-06-13