ZDI-23-779: Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default configuration.
Affected Software
1 affected component
Unified Automation UaGateway
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:06 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-779?
The severity of ZDI-23-779 is classified as a denial-of-service vulnerability.
2
How do I fix ZDI-23-779?
To fix ZDI-23-779, update to the latest version of Unified Automation UaGateway as per the vendor's security advisory.
3
Who is affected by ZDI-23-779?
ZDI-23-779 affects installations of Unified Automation UaGateway that are in their default configuration.
4
Does ZDI-23-779 require authentication to exploit?
Yes, ZDI-23-779 requires authentication to exploit when the product is in its default configuration.
5
What type of attack does ZDI-23-779 enable?
ZDI-23-779 enables remote attackers to create a denial-of-service condition on the affected systems.