ZDI-CAN-17196: ZDI-23-743: (Pwn2Own) Unified Automation OPC UA C++ Demo Server DemoDynamicNodesDeleteDynamicNode Use-After Free Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Unified Automation OPC UA C++ Demo Server
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-17196?
The severity of ZDI-CAN-17196 is classified as high due to its potential to create a denial-of-service condition.
2
How do I fix ZDI-CAN-17196?
To fix ZDI-CAN-17196, you should apply the latest patches or updates provided by Unified Automation for the OPC UA C++ Demo Server.
3
What type of attacks can exploit ZDI-CAN-17196?
ZDI-CAN-17196 can be exploited by remote attackers to create a denial-of-service condition without requiring authentication.
4
Which software is affected by ZDI-CAN-17196?
ZDI-CAN-17196 specifically affects Unified Automation OPC UA C++ Demo Server installations.
5
Is authentication required to exploit ZDI-CAN-17196?
No, authentication is not required to exploit ZDI-CAN-17196.