First published: Wed Nov 10 2021(Updated: )
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Softing Smartlink Hw-dp | <=1.10 | |
Softing uaToolkit Embedded | <1.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40872 is a vulnerability discovered in Softing Industrial Automation uaToolkit Embedded before version 1.40.
CVE-2021-40872 has a severity rating of 7.5, which is considered high.
CVE-2021-40872 affects Softing Smartlink Hw-dp versions up to and including 1.10.
CVE-2021-40872 affects Softing uaToolkit Embedded versions up to but not including 1.40.
To fix CVE-2021-40872, users should upgrade Softing uaToolkit Embedded to version 1.40 or later.