CVE-2022-29862
Description
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Infinite loop in OPC UA .NET Standard Stack 1.04.368 allows remote attackers to hang the application via crafted message.
Vulnerability
Description An infinite loop vulnerability (CWE-835) exists in the OPC UA .NET Standard Stack version 1.04.368. The flaw occurs when the stack processes a specially crafted OPC UA message, causing the application to enter an infinite loop and become unresponsive [3]. This issue affects the core library of the OPC UA .NET reference implementation [1].
Exploitation
A remote attacker can exploit this vulnerability by sending a malicious OPC UA message to a server or client using the affected stack. No authentication is required, as the message is processed before any security checks are performed. The attack vector is network-based, making it accessible to any attacker who can reach the target application over the network [3].
Impact
Successful exploitation results in a denial of service (DoS) condition. The target application hangs and becomes unable to process legitimate OPC UA requests, disrupting industrial automation and control systems that rely on OPC UA communications [2].
Mitigation
The OPC Foundation has released a security bulletin addressing this vulnerability [2]. Users are advised to update to a patched version of the OPC UA .NET Standard Stack. The official GitHub repository provides the latest releases and security advisories [1][3].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
OPCFoundation.NetStandard.Opc.Ua.CoreNuGet | < 1.4.368.58 | 1.4.368.58 |
Affected products
2- OPC UA/OPC UA .NET Standard Stackdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-5q2v-6j86-5h9vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-29862ghsaADVISORY
- files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-29862.pdfghsax_refsource_MISCWEB
- github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-5q2v-6j86-5h9vghsaWEB
- opcfoundation.org/security/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.