ICSA-21-133-04: Unified automation .net based opc ua client/server sdk vulnerability
Affected Software
1 affected component
Unified Automation GmbH Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only)
Event History
Jan 30, 2025
Advisory Published
10:58 AM
Frequently Asked Questions
1
What is the severity of ICSA-21-133-04?
The severity of ICSA-21-133-04 is rated as high due to multiple vulnerabilities that could allow an attacker to execute arbitrary code.
2
How do I fix ICSA-21-133-04?
To fix ICSA-21-133-04, upgrade to Unified Automation GmbH's .NET based OPC UA Client/Server SDK Bundle version V3.0.8 or later.
3
What vulnerabilities are addressed in ICSA-21-133-04?
ICSA-21-133-04 addresses vulnerabilities including stack-based buffer overflow and improper input validation.
4
Who is affected by ICSA-21-133-04?
Organizations using Unified Automation GmbH Unified Automation .NET based OPC UA Client/Server SDK Bundle versions V3.0.7 and prior on supported .NET Frameworks are affected.
5
What are the impacts of ICSA-21-133-04 if left unaddressed?
If unaddressed, ICSA-21-133-04 could allow an attacker to exploit the vulnerabilities to gain unauthorized access and potentially control the system.