CVE-2021-45117: Null Pointer Dereference
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-45117.
What is the severity of CVE-2021-45117?
The severity of CVE-2021-45117 is medium with a CVSS score of 6.5.
Which software is affected by CVE-2021-45117?
The software affected by CVE-2021-45117 includes Opcfoundation Ua-nodeset, Siemens Simatic Net Pc (versions 14, 15, 16, and 17), Siemens Sitop Manager, and Siemens Telecontrol Server Basic (version 3.0).
How can the vulnerability in OPC autogenerated ANSI C stack stubs be exploited?
The vulnerability in OPC autogenerated ANSI C stack stubs can be exploited by triggering an error case that leads to a NULL pointer dereference.
Are there any references available for CVE-2021-45117?
Yes, there are references available for CVE-2021-45117. You can find them at the following links: [link1](https://cert-portal.siemens.com/productcert/pdf/ssa-285795.pdf), [link2](https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-45117.pdf), [link3](https://www.youtube.com/watch?v=qv-RBdCaV4k).