ZDI-23-778: (Pwn2Own) Prosys OPC UA Simulation Server OpenSecureChannel Resource Exhaustion Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Prosys OPC UA Simulation Server. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Prosys OPC UA Simulation Server
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-778?
The severity of ZDI-23-778 is high due to its ability to cause a denial-of-service condition.
2
How do I fix ZDI-23-778?
To fix ZDI-23-778, update the Prosys OPC UA Simulation Server to the latest version provided by the vendor.
3
What type of attack can ZDI-23-778 facilitate?
ZDI-23-778 facilitates a denial-of-service attack which disrupts services on affected installations.
4
Is authentication required to exploit ZDI-23-778?
No, authentication is not required to exploit ZDI-23-778, making it more dangerous.
5
Which software is affected by ZDI-23-778?
ZDI-23-778 affects the Prosys OPC UA Simulation Server.