CVE-2022-29866: High severity opc foundation .net standard stack vulnerability
Published Jun 16, 2022
·Updated
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
Affected Software
1 affected component
opcfoundation Ua .net Standard Stack<1.4.368.58
Remediation
Event History
Jun 16, 2022
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29866?
The severity of CVE-2022-29866 is high with a CVSS score of 7.5.
2
How does CVE-2022-29866 affect OPC UA .NET Standard Stack?
CVE-2022-29866 affects OPC UA .NET Standard Stack 1.04.368.
3
How can a remote attacker exploit CVE-2022-29866?
A remote attacker can exploit CVE-2022-29866 by sending a crafted request that triggers Uncontrolled Resource Consumption, causing the server to exhaust its memory resources.
4
What software versions are affected by CVE-2022-29866?
OPC UA .NET Standard Stack versions up to and exclusive of 1.04.368.58 are affected by CVE-2022-29866.
5
Is there a fix available for CVE-2022-29866?
Yes, an update to version 1.04.368.58 or later of OPC UA .NET Standard Stack fixes CVE-2022-29866.