CVE-2021-40142: Buffer Overflow
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-40142?
CVE-2021-40142 is a vulnerability in OPC Foundation Local Discovery Server (LDS) before 1.04.402.463 that can lead to a denial of service (DoS) by sending specially crafted messages.
Which software is affected by CVE-2021-40142?
The affected software includes Opcfoundation Local Discover Server (up to version 1.04.402.463), Siemens Simatic Process Historian Opc Ua Server Firmware (up to version 2022), and Siemens Simatic Net Pc (versions 14, 15, 16, and 17).
What is the severity of CVE-2021-40142?
CVE-2021-40142 has a severity rating of 7.5 (high).
How can I fix CVE-2021-40142?
To fix CVE-2021-40142, update to the latest version of OPC Foundation Local Discovery Server (LDS) (1.04.402.463 or higher) and apply any patches or updates provided by Siemens for their affected software.
Where can I find more information about CVE-2021-40142?
You can find more information about CVE-2021-40142 in the Siemens ProductCERT advisory, the OPC Foundation Security Bulletin, and the CERT-CC vulnerability note.