First published: Fri Aug 27 2021(Updated: )
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opcfoundation Local Discover Server | <1.04.402.463 | |
Siemens Simatic Process Historian Opc Ua Server Firmware | <2022 | |
Siemens Simatic Process Historian Opc Ua Server Firmware | =2022 | |
Siemens Simatic Process Historian Opc Ua Server | ||
Siemens Simatic Net Pc | =14 | |
Siemens Simatic Net Pc | =15 | |
Siemens Simatic Net Pc | =16 | |
Siemens Simatic Net Pc | =17 | |
Siemens Simatic WinCC | ||
Siemens Simatic Wincc Runtime | ||
Siemens Simatic Wincc Unified Scada Runtime | ||
Siemens Telecontrol Server Basic | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40142 is a vulnerability in OPC Foundation Local Discovery Server (LDS) before 1.04.402.463 that can lead to a denial of service (DoS) by sending specially crafted messages.
The affected software includes Opcfoundation Local Discover Server (up to version 1.04.402.463), Siemens Simatic Process Historian Opc Ua Server Firmware (up to version 2022), and Siemens Simatic Net Pc (versions 14, 15, 16, and 17).
CVE-2021-40142 has a severity rating of 7.5 (high).
To fix CVE-2021-40142, update to the latest version of OPC Foundation Local Discovery Server (LDS) (1.04.402.463 or higher) and apply any patches or updates provided by Siemens for their affected software.
You can find more information about CVE-2021-40142 in the Siemens ProductCERT advisory, the OPC Foundation Security Bulletin, and the CERT-CC vulnerability note.