CVE-2023-27321: (Pwn2Own) OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20505.
Other sources
This security update resolves a vulnerability in the OPC UA .NET Standard Reference Server that allows remote attackers to send malicious requests that consume all memory available to the server.
https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2023-27321.pdf
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27321?
CVE-2023-27321 is classified as a denial-of-service vulnerability that can severely impact affected installations.
How do I fix CVE-2023-27321?
To mitigate CVE-2023-27321, upgrade to OPCFoundation.NetStandard.Opc.Ua.Server version 1.4.371.86 or later.
What kind of attack does CVE-2023-27321 facilitate?
CVE-2023-27321 allows remote attackers to create a denial-of-service condition on affected systems.
Is authentication required to exploit CVE-2023-27321?
No, authentication is not required to exploit CVE-2023-27321.
Which software versions are affected by CVE-2023-27321?
CVE-2023-27321 affects versions of OPC Foundation UA .NET Standard earlier than 1.4.371.86.