Apache PLC4X Java (PLC4J) deployments using versions from 0.10.0 before 1.0.0 are affected. Version 1.0.0 is listed as unaffected.
No. The affected OPC UA parsing occurs while the secure channel and session are being established, before the server identity is bound, so an attacker able to impersonate the server can still trigger the issue.
The issue is remotely reachable without authentication or user interaction. A malicious device, or an attacker impersonating a device, can send crafted protocol data to exhaust the client application's memory or stack and cause denial of service.
Check the Apache PLC4X version used by the Java client application. Versions from 0.10.0 up to, but not including, 1.0.0 are listed as affected; 1.0.0 is listed as unaffected.