CVE-2023-32171: (Pwn2Own) Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability. The specific flaw exists within the ImportCsv method. A crafted XML payload can cause a null pointer dereference. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32171?
CVE-2023-32171 has a severity rating that indicates it can lead to a denial-of-service condition.
How do I fix CVE-2023-32171?
To mitigate CVE-2023-32171, apply the latest security updates provided by Unified Automation for UaGateway.
Who can exploit CVE-2023-32171?
CVE-2023-32171 can be exploited by remote attackers who have the required authentication to access the affected system.
What is the attack vector for CVE-2023-32171?
The attack vector for CVE-2023-32171 involves sending a crafted XML payload using the ImportCsv method.
Which product is affected by CVE-2023-32171?
CVE-2023-32171 affects the Unified Automation UaGateway software.