CVE-2022-44725: High severity opcfoundation Local Discovery Server vulnerability
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44725?
CVE-2022-44725 is a vulnerability in the OPC Foundation Local Discovery Server (LDS) that allows a normal user to create a malicious file that is loaded by LDS, running as a high-privilege user.
What is the severity of CVE-2022-44725?
CVE-2022-44725 has a severity value of 7.8 (high).
How does CVE-2022-44725 affect the OPC Foundation Local Discovery Server?
CVE-2022-44725 affects the OPC Foundation Local Discovery Server through version 1.04.403.478, allowing a user to exploit a hard-coded file path and execute malicious code.
How can a normal user exploit CVE-2022-44725?
A normal user can create a malicious file that is loaded by the OPC Foundation Local Discovery Server, running as a high-privilege user.
Is there a fix for CVE-2022-44725?
At the time of writing, there is no available fix for CVE-2022-44725. It is recommended to apply security best practices and monitor updates from the OPC Foundation.