ZDI-CAN-20508: ZDI-23-1065: (0Day) (Pwn2Own) Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability
Published Aug 9, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Softing edgeConnector Siemens
Event History
Aug 9, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 24, 2025
Advisory Published
via ZDI·04:14 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20508?
The severity of ZDI-CAN-20508 is high due to its ability to cause a denial-of-service condition without requiring authentication.
2
How do I fix ZDI-CAN-20508?
To fix ZDI-CAN-20508, update the Softing edgeConnector Siemens to the latest version that addresses the vulnerability.
3
Who is affected by ZDI-CAN-20508?
Organizations using the Softing edgeConnector Siemens software are affected by ZDI-CAN-20508.
4
What kind of attack does ZDI-CAN-20508 facilitate?
ZDI-CAN-20508 facilitates remote denial-of-service attacks against the affected installations.
5
Is authentication required to exploit ZDI-CAN-20508?
No, authentication is not required to exploit the ZDI-CAN-20508 vulnerability.