Skip to main content

Vendor archive

opcfoundation CVEs

Beta · best-effort

26 CVEs tagged to vendor opcfoundation0 Critical, 19 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-42513

Published Feb 10, 2025

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42512

Published Feb 10, 2025

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27321

Published May 7, 2024

OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service cond…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31048

Published Dec 12, 2023

The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44725

Published Nov 17, 2022

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29866

Published Jun 16, 2022

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29864

Published Jun 16, 2022

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30551

Published May 20, 2022

OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40142

Published Aug 27, 2021

In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access…

CVSS 7.5 · High

CVE-2020-29457

Published Feb 16, 2021

A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17443

Published Jun 13, 2018

OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to trigger a crash by placing invalid data…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2