CVE-2024-25075: Medium severity Softing uaToolkit Embedded vulnerability
An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is mishandled, leading to memory consumption. When that happens often enough, the device will be out of memory, i.e., a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25075?
CVE-2024-25075 is considered a denial of service vulnerability due to excessive memory consumption.
How do I fix CVE-2024-25075?
To mitigate CVE-2024-25075, update Softing uaToolkit Embedded to version 1.41.1 or later.
What causes CVE-2024-25075?
CVE-2024-25075 is caused by mishandling of publish responses when a subscription with a very low MaxNotificationPerPublish parameter is created.
Who is affected by CVE-2024-25075?
Users of Softing uaToolkit Embedded versions prior to 1.41.1 are affected by CVE-2024-25075.
What are the potential impacts of CVE-2024-25075?
The potential impacts of CVE-2024-25075 include device crashes and denial of service due to out of memory conditions.