An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.
References
Link | Resource |
---|---|
https://industrial.softing.com/ | Vendor Advisory |
https://industrial.softing.com/fileadmin/sof-files/pdf/ia/support/Security_Bulletin_CVE-2021-40872.pdf | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-11-10T22:46:19
Updated: 2021-11-10T22:46:19
Reserved: 2021-09-13T00:00:00
Link: CVE-2021-40872
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-11-10T23:15:08.300
Modified: 2021-11-16T15:01:33.820
Link: CVE-2021-40872
JSON object: View
Redhat Information
No data.
CWE