CVE-2022-39823: Use After Free
Published Oct 20, 2022
·Updated
An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the server limit on continuation points may cause a use-after-free error
Affected Software
2 affected components
Softing OPC>=5.20<=5.22
Softing Opc Ua C\+\+ Software Development Kit>=5.70<=6.00
Event History
Oct 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-39823?
CVE-2022-39823 is a vulnerability discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10 that can cause a use-after-free error when an OPC/UA browse request exceeds the server limit on continuation points.
2
How severe is CVE-2022-39823?
CVE-2022-39823 has a severity rating of 7.5 out of 10 (high).
3
Which software versions are affected by CVE-2022-39823?
CVE-2022-39823 affects Softing OPC UA C++ SDK versions 5.66 through 6.x before 6.10.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2022-39823.
5
How can CVE-2022-39823 be mitigated?
To mitigate CVE-2022-39823, users are advised to update to Softing OPC UA C++ SDK version 6.10 or later.