ZDI-23-775: (Pwn2Own) Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. User interaction is required to exploit this vulnerability in that the target must choose to accept a client certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-775?
The severity of ZDI-23-775 is classified as a denial-of-service vulnerability.
How can I fix ZDI-23-775?
To mitigate ZDI-23-775, ensure that only trusted clients are allowed to connect and validate client certificates meticulously.
What impact does ZDI-23-775 have on Unified Automation UaGateway?
ZDI-23-775 allows remote attackers to create a denial-of-service condition, affecting the availability of Unified Automation UaGateway.
Are there any prerequisites for exploiting ZDI-23-775?
Yes, exploitation of ZDI-23-775 requires user interaction, specifically the acceptance of a client certificate.
Which versions of Unified Automation UaGateway are affected by ZDI-23-775?
ZDI-23-775 affects certain installations of Unified Automation UaGateway, though specific version details are not mentioned.