Beveiligingsadvies

CVE-2022-25302

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-08-23 05:00:17
Laatst bijgewerkt 2024-09-17 03:53:54
Toegewezen door snyk
CVSS-score 7.5
Status PUBLISHED

Beschrijving

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed casting when unvalidated data is forwarded to boost::get function in OpcUaNodeIdBase.h. Exploiting this vulnerability is possible when sending a specifically crafted OPC UA message with a special encoded NodeId.