ZDI-23-548: (Pwn2Own) OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-548?
ZDI-23-548 is classified as a denial-of-service vulnerability that can be exploited without authentication.
How do I fix ZDI-23-548?
To remediate ZDI-23-548, it is recommended to update the OPC Foundation UA .NET Standard software to the latest version provided by the vendor.
What types of attacks can be executed due to ZDI-23-548?
ZDI-23-548 allows remote attackers to create a denial-of-service condition, disrupting the service of the affected installations.
Are there any workarounds for ZDI-23-548?
Currently, there are no official workarounds for mitigating the impact of ZDI-23-548 other than applying the software update.
Who is affected by ZDI-23-548?
The vulnerability ZDI-23-548 affects installations of OPC Foundation UA .NET Standard.