Use-After-Free Vulnerability in Softing OPC UA C++ SDK
CVE-2022-39823

7.5HIGH

Key Information:

Vendor

Softing

Vendor
CVE Published:
20 October 2022

What is CVE-2022-39823?

An issue has been identified within the Softing OPC UA C++ SDK versions 5.66 through 6.x prior to 6.10. This vulnerability arises when an OPC/UA browse request exceeds the server's limit on continuation points, potentially leading to a use-after-free error. This situation may allow an attacker to exploit the flaw, resulting in unintended behavior within the SDK. It is crucial for users of affected versions to apply necessary precautions and updates to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.