ZDI-23-776: (Pwn2Own) Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Unified Automation UaGateway
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:06 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-776?
The severity of ZDI-23-776 is categorized as a denial-of-service vulnerability.
2
How do I fix ZDI-23-776?
To mitigate ZDI-23-776, ensure that your Unified Automation UaGateway is updated to the latest version provided by the vendor.
3
What version of UaGateway is affected by ZDI-23-776?
ZDI-23-776 affects multiple versions of Unified Automation UaGateway prior to the vendor's patch release.
4
Is authentication required to exploit ZDI-23-776?
Yes, authentication is required to exploit the ZDI-23-776 vulnerability.
5
What impact does ZDI-23-776 have on affected systems?
ZDI-23-776 can lead to a denial-of-service condition, affecting the availability of affected installations.