ZDI-22-1029: (Pwn2Own) Unified Automation OPC UA C++ Infinite Loop Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of certificates. A crafted certificate can force the server into an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-22-1029?
The severity of ZDI-22-1029 is classified as critical due to the potential for remote denial-of-service attacks.
How do I fix ZDI-22-1029?
To fix ZDI-22-1029, update to the latest version of Unified Automation OPC UA C++ Demo Server as provided in their security advisories.
What types of attacks can exploit ZDI-22-1029?
ZDI-22-1029 can be exploited to perform remote denial-of-service attacks against affected installations.
Is authentication required to exploit ZDI-22-1029?
No, authentication is not required to exploit the ZDI-22-1029 vulnerability.
Which software is affected by ZDI-22-1029?
The affected software for ZDI-22-1029 is Unified Automation OPC UA C++ Demo Server.