CVE-2021-27434: Infoleak
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27434?
CVE-2021-27434 is a vulnerability in the Unified Automation .NET based OPC UA Client/Server SDK Bundle with versions up to 3.0.7, which allows an attacker to trigger a stack overflow.
What is the severity of CVE-2021-27434?
CVE-2021-27434 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2021-27434?
Versions 3.0.7 and prior of the Unified Automation .NET based OPC UA Client/Server SDK Bundle (for .NET Framework 4.5, 4.0, and 3.5) are affected.
How can an attacker exploit CVE-2021-27434?
An attacker can exploit CVE-2021-27434 by triggering an uncontrolled recursion, leading to a stack overflow.
Is Microsoft .NET Framework vulnerable to CVE-2021-27434?
Microsoft .NET Framework versions 3.5, 4.0, and 4.5 are not vulnerable to CVE-2021-27434.