First published: Thu May 20 2021(Updated: )
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Unified-automation .net Based Opc Ua Client\/server Sdk | <=3.0.7 | |
Microsoft .NET Framework | =3.5 | |
Microsoft .NET Framework | =4.0 | |
Microsoft .NET Framework | =4.5 | |
Unified Automation GmbH Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27434 is a vulnerability in the Unified Automation .NET based OPC UA Client/Server SDK Bundle with versions up to 3.0.7, which allows an attacker to trigger a stack overflow.
CVE-2021-27434 has a severity rating of 7.5 (high).
Versions 3.0.7 and prior of the Unified Automation .NET based OPC UA Client/Server SDK Bundle (for .NET Framework 4.5, 4.0, and 3.5) are affected.
An attacker can exploit CVE-2021-27434 by triggering an uncontrolled recursion, leading to a stack overflow.
Microsoft .NET Framework versions 3.5, 4.0, and 4.5 are not vulnerable to CVE-2021-27434.