ZDI-23-709: (Pwn2Own) Prosys OPC UA Simulation Server Resource Exhaustion Denial-of-Service Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Prosys OPC UA Simulation Server. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Prosys OPC UA Simulation Server
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-709?
The vulnerability ZDI-23-709 has a critical severity level due to its potential to cause denial-of-service conditions.
2
How do I fix ZDI-23-709?
To mitigate vulnerability ZDI-23-709, ensure you apply the latest updates and patches provided by Prosys for the OPC UA Simulation Server.
3
Who is affected by ZDI-23-709?
ZDI-23-709 affects all installations of Prosys OPC UA Simulation Server, regardless of version.
4
Is authentication needed to exploit ZDI-23-709?
No, authentication is not required to exploit the vulnerability ZDI-23-709.
5
What type of attack does ZDI-23-709 enable?
ZDI-23-709 enables remote attackers to create a denial-of-service condition on affected systems.