CVE-2023-27321

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-27321
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27321.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-27321
Aliases
Published
2024-05-07T23:15:15Z
Modified
2025-10-21T13:12:35.484940Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20505.

References

Affected packages

Git / github.com/opcfoundation/ua-.netstandard

Affected ranges

Type
GIT
Repo
https://github.com/opcfoundation/ua-.netstandard
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.03.350
1.03.350.6
1.03.351.7
1.03.352.10
1.04.353.15
1.04.354.21
1.04.354.23
1.4.355.26
1.4.356.27
1.4.357.28
1.4.358.30
1.4.359.31
1.4.360.33
1.4.361.39
1.4.362.42
1.4.363.49
1.4.366.31-preview
1.4.367.64-preview
1.4.368.27-preview
1.4.368.33
1.4.368.52-preview
1.4.368.53
1.4.368.58
1.4.371.41
1.4.371.50
1.4.371.60