ZDI-CAN-20544: ZDI-23-778: (Pwn2Own) Prosys OPC UA Simulation Server OpenSecureChannel Resource Exhaustion Denial-of-Service Vulnerability
Published May 31, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Prosys OPC UA Simulation Server. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Prosys OPC UA Simulation Server
Event History
May 31, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20544?
The severity of ZDI-CAN-20544 is critical due to its potential to cause a denial-of-service condition.
2
How do I fix ZDI-CAN-20544?
To fix ZDI-CAN-20544, apply the latest patch provided by Prosys for the OPC UA Simulation Server.
3
Who can exploit ZDI-CAN-20544?
ZDI-CAN-20544 can be exploited by remote attackers without the need for authentication.
4
What are the impacts of ZDI-CAN-20544?
The impact of ZDI-CAN-20544 is a denial-of-service condition on affected installations of the Prosys OPC UA Simulation Server.
5
Which versions of Prosys OPC UA Simulation Server are affected by ZDI-CAN-20544?
All versions of Prosys OPC UA Simulation Server are affected by ZDI-CAN-20544.