ZDI-23-1286: Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability
Published Aug 30, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Unified Automation UaGateway
Event History
Aug 30, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:25 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-1286?
The severity of ZDI-23-1286 is high as it allows remote attackers to create a denial-of-service condition.
2
How do I fix ZDI-23-1286?
To fix ZDI-23-1286, update to the latest version of Unified Automation UaGateway that addresses this vulnerability.
3
Is authentication required to exploit ZDI-23-1286?
No, authentication is not required to exploit ZDI-23-1286, making it more critical.
4
What type of attack does ZDI-23-1286 facilitate?
ZDI-23-1286 facilitates a denial-of-service attack that can incapacitate affected UaGateway installations.
5
What products are affected by ZDI-23-1286?
ZDI-23-1286 affects Unified Automation UaGateway installations specifically.