ZDI-CAN-20494: ZDI-23-775: (Pwn2Own) Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. User interaction is required to exploit this vulnerability in that the target must choose to accept a client certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20494?
The severity of ZDI-CAN-20494 is considered high due to the potential for remote denial-of-service attacks.
How do I fix ZDI-CAN-20494?
To fix ZDI-CAN-20494, ensure that you are using the latest version of Unified Automation UaGateway, and apply any available updates.
What type of attack is associated with ZDI-CAN-20494?
ZDI-CAN-20494 is associated with remote denial-of-service attacks that require user interaction.
Is user interaction required to exploit ZDI-CAN-20494?
Yes, user interaction is required because the target must accept a client certificate for the exploit to succeed.
What systems are vulnerable to ZDI-CAN-20494?
ZDI-CAN-20494 affects installations of Unified Automation UaGateway software.