VYPR
High severityNVD Advisory· Published Jun 16, 2022· Updated Aug 3, 2024

CVE-2022-29862

CVE-2022-29862

Description

An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Infinite loop in OPC UA .NET Standard Stack 1.04.368 allows remote attackers to hang the application via crafted message.

Vulnerability

Description An infinite loop vulnerability (CWE-835) exists in the OPC UA .NET Standard Stack version 1.04.368. The flaw occurs when the stack processes a specially crafted OPC UA message, causing the application to enter an infinite loop and become unresponsive [3]. This issue affects the core library of the OPC UA .NET reference implementation [1].

Exploitation

A remote attacker can exploit this vulnerability by sending a malicious OPC UA message to a server or client using the affected stack. No authentication is required, as the message is processed before any security checks are performed. The attack vector is network-based, making it accessible to any attacker who can reach the target application over the network [3].

Impact

Successful exploitation results in a denial of service (DoS) condition. The target application hangs and becomes unable to process legitimate OPC UA requests, disrupting industrial automation and control systems that rely on OPC UA communications [2].

Mitigation

The OPC Foundation has released a security bulletin addressing this vulnerability [2]. Users are advised to update to a patched version of the OPC UA .NET Standard Stack. The official GitHub repository provides the latest releases and security advisories [1][3].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
OPCFoundation.NetStandard.Opc.Ua.CoreNuGet
< 1.4.368.581.4.368.58

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.