ZDI-23-777: (Pwn2Own) Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Unified Automation UaGateway
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:06 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-777?
The severity of ZDI-23-777 is high due to its potential to cause denial-of-service on affected systems.
2
How do I fix ZDI-23-777?
To fix ZDI-23-777, apply the latest security updates provided by Unified Automation for UaGateway.
3
What systems are affected by ZDI-23-777?
ZDI-23-777 affects installations of Unified Automation UaGateway.
4
Is authentication required to exploit ZDI-23-777?
Yes, authentication is required to exploit the ZDI-23-777 vulnerability.
5
What type of attack does ZDI-23-777 facilitate?
ZDI-23-777 facilitates a remote denial-of-service attack on the affected installations.