CVE-2023-41185: Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of client certificates. When parsing the certificate length field, the process does not properly validate user-supplied data, which can result in an integer overflow. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41185?
CVE-2023-41185 is classified as a high severity vulnerability due to its potential to allow remote denial-of-service attacks.
How do I fix CVE-2023-41185?
To mitigate CVE-2023-41185, update Unified Automation UaGateway to the latest version that addresses this vulnerability.
What kind of attack can be executed using CVE-2023-41185?
CVE-2023-41185 allows remote attackers to create a denial-of-service condition that impacts the availability of affected installations.
Is authentication required to exploit CVE-2023-41185?
No, authentication is not required to exploit CVE-2023-41185, making it particularly dangerous.
What software is affected by CVE-2023-41185?
CVE-2023-41185 specifically affects Unified Automation UaGateway.