CVE-2023-32170: (Pwn2Own) Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. User interaction is required to exploit this vulnerability in that the target must choose to accept a client certificate. The specific flaw exists within the processing of client certificates. The issue results from the lack of proper validation of certificate data. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32170?
CVE-2023-32170 is classified as a denial-of-service vulnerability that could impact the availability of affected systems.
How do I fix CVE-2023-32170?
To address CVE-2023-32170, ensure that your Unified Automation UaGateway is updated to the latest version which includes a fix.
What software is affected by CVE-2023-32170?
CVE-2023-32170 affects Unified Automation's UaGateway software.
What type of attack does CVE-2023-32170 facilitate?
CVE-2023-32170 facilitates a denial-of-service condition that requires user interaction, as the target must accept a client certificate.
Who can exploit CVE-2023-32170?
Remote attackers can exploit CVE-2023-32170, but user interaction is necessary for the attack to succeed.