CVE-2023-31048: Infoleak
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.
Other sources
This security update resolves a vulnerability in the OPC UA .NET Standard Reference Server that allows remote attackers to send malicious requests that expose sensitive information.
https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2023-31048.pdf
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31048?
CVE-2023-31048 is classified as a Medium severity vulnerability.
How do I fix CVE-2023-31048?
To fix CVE-2023-31048, upgrade to OPC Foundation .NET Standard Reference Server version 1.4.371.86 or later.
What kind of information does CVE-2023-31048 expose?
CVE-2023-31048 exposes sensitive information contained within error messages that can be viewed by remote attackers.
Which versions of the OPC UA .NET Standard Reference Server are affected by CVE-2023-31048?
CVE-2023-31048 affects all versions of the OPC UA .NET Standard Reference Server prior to 1.4.371.86.
What can attackers do with the vulnerability in CVE-2023-31048?
Attackers can send malicious requests that may cause the server to leak sensitive information through error messages.