Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Opc Ua Stack Project Subscribe
Filtered by product Opc Ua Stack
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25302 1 Opc Ua Stack Project 1 Opc Ua Stack 2022-08-25 N/A 7.5 HIGH
All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed casting when unvalidated data is forwarded to boost::get function in OpcUaNodeIdBase.h. Exploiting this vulnerability is possible when sending a specifically crafted OPC UA message with a special encoded NodeId.