CVE-2021-40872: High severity softing smartlink hw-dp vulnerability
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40872?
CVE-2021-40872 is a vulnerability discovered in Softing Industrial Automation uaToolkit Embedded before version 1.40.
What is the severity of CVE-2021-40872?
CVE-2021-40872 has a severity rating of 7.5, which is considered high.
How does CVE-2021-40872 affect Softing Smartlink Hw-dp?
CVE-2021-40872 affects Softing Smartlink Hw-dp versions up to and including 1.10.
How does CVE-2021-40872 affect Softing uaToolkit Embedded?
CVE-2021-40872 affects Softing uaToolkit Embedded versions up to but not including 1.40.
How can I fix CVE-2021-40872?
To fix CVE-2021-40872, users should upgrade Softing uaToolkit Embedded to version 1.40 or later.