Uncontrolled Resource Consumption in OPC UA Tunneller by AutomationDirect
CVE-2020-27295

7.5HIGH

Key Information:

Vendor

Honeywell

Vendor
CVE Published:
26 January 2021

What is CVE-2020-27295?

The OPC UA Tunneller by AutomationDirect exhibits uncontrolled resource consumption vulnerabilities that can be exploited by attackers. By leveraging these weaknesses, an attacker could potentially lead to a denial-of-service (DoS) condition, affecting the availability of the service and disrupting operations. This issue is present in versions prior to 6.3.0.8233. It is crucial for users to review their deployments and consider applying the necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

OPC UA Tunneller All versions prior to 6.3.0.8233

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.