High severity7.5NVD Advisory· Published Aug 27, 2021· Updated Jun 17, 2026
CVE-2021-40142
CVE-2021-40142
Description
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Affected products
13- cpe:2.3:a:opcfoundation:local_discover_server:*:*:*:*:*:*:*:*Range: <1.04.402.463
cpe:2.3:a:siemens:simatic_net_pc:14:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:siemens:simatic_net_pc:14:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_net_pc:15:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_net_pc:17:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_wincc:-:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_wincc_runtime:-:*:*:*:professional:*:*:*
- cpe:2.3:a:siemens:simatic_wincc_unified_scada_runtime:-:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:telecontrol_server_basic:3.0:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:*:*:*:*:*:*:*:*range: <2022
- cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:2022:-:*:*:*:*:*:*
- OPC Foundation/Local Discovery Server (LDS)description
- Range: <1.04.402.463
Patches
Vulnerability mechanics
References
3- cert-portal.siemens.com/productcert/pdf/ssa-321292.pdfnvdPatchThird Party Advisory
- files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-40142.pdfnvdPatchVendor Advisory
- opcfoundation.org/security-bulletins/nvdVendor Advisory
News mentions
0No linked articles in our index yet.