ZDI-CAN-20495: ZDI-23-776: (Pwn2Own) Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Unified Automation UaGateway
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:06 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20495?
ZDI-CAN-20495 is classified as a denial-of-service vulnerability.
2
How do I fix ZDI-CAN-20495?
To mitigate ZDI-CAN-20495, ensure that you apply the latest security patches provided by Unified Automation for UaGateway.
3
What type of attacks are possible with ZDI-CAN-20495?
ZDI-CAN-20495 allows remote attackers to initiate a denial-of-service condition on affected installations.
4
Is authentication required to exploit ZDI-CAN-20495?
Yes, authentication is required to exploit the ZDI-CAN-20495 vulnerability.
5
Which software versions are affected by ZDI-CAN-20495?
ZDI-CAN-20495 affects specific versions of Unified Automation UaGateway, so check for updated advisories from the vendor.