CVE-2021-32994: Softing OPC-UA C++ SDK Improper Restriction of Operations within the Bounds of a Memory Buffer
Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Softing OPC UA C++ SDK vulnerability?
The vulnerability ID for this Softing OPC UA C++ SDK vulnerability is CVE-2021-32994.
What is the severity of CVE-2021-32994?
The severity of CVE-2021-32994 is high with a score of 7.5.
What is the description of CVE-2021-32994?
CVE-2021-32994 is a vulnerability in Softing OPC UA C++ SDK that may allow an attacker to crash the software by sending specially crafted packets to access unexpected memory locations.
Which versions of Softing OPC UA C++ SDK are affected by CVE-2021-32994?
Softing OPC UA C++ SDK versions from 5.59 to 5.64 are affected by CVE-2021-32994.
Is there a fix available for CVE-2021-32994?
Yes, a fix is available for CVE-2021-32994. It is recommended to update to version 5.65.0 or higher of Softing OPC UA C++ SDK.