First published: Mon Mar 21 2022(Updated: )
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opcfoundation Ua-nodeset | <1.05.01 | |
Siemens Simatic Net Pc | =14 | |
Siemens Simatic Net Pc | =15 | |
Siemens Simatic Net Pc | =16 | |
Siemens Simatic Net Pc | =17 | |
Siemens Sitop Manager | ||
Siemens Telecontrol Server Basic | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-45117.
The severity of CVE-2021-45117 is medium with a CVSS score of 6.5.
The software affected by CVE-2021-45117 includes Opcfoundation Ua-nodeset, Siemens Simatic Net Pc (versions 14, 15, 16, and 17), Siemens Sitop Manager, and Siemens Telecontrol Server Basic (version 3.0).
The vulnerability in OPC autogenerated ANSI C stack stubs can be exploited by triggering an error case that leads to a NULL pointer dereference.
Yes, there are references available for CVE-2021-45117. You can find them at the following links: [link1](https://cert-portal.siemens.com/productcert/pdf/ssa-285795.pdf), [link2](https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-45117.pdf), [link3](https://www.youtube.com/watch?v=qv-RBdCaV4k).