ZDI-CAN-20497: ZDI-23-777: (Pwn2Own) Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20497?
The severity of ZDI-CAN-20497 is classified as a denial-of-service vulnerability, which can disrupt affected installations.
How do I fix ZDI-CAN-20497?
To fix ZDI-CAN-20497, ensure that your Unified Automation UaGateway is updated to the latest version that addresses this vulnerability.
Who can exploit ZDI-CAN-20497?
ZDI-CAN-20497 can be exploited by remote attackers who have obtained authentication to the affected UaGateway installations.
What are the impacts of ZDI-CAN-20497?
The impact of ZDI-CAN-20497 is a potential denial-of-service condition, which can render the service unavailable to users.
Is authentication required to exploit ZDI-CAN-20497?
Yes, authentication is required to exploit the ZDI-CAN-20497 vulnerability, limiting its potential attackers.