VYPR

Ua .net Standard Stack

by Opcfoundation

Source repositories

CVEs (9)

  • CVE-2024-42512HigFeb 10, 2025
    risk 0.49cvss 8.6epss 0.01

    Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.

  • CVE-2022-29866HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

  • CVE-2022-29864HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

  • CVE-2022-29863HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

  • CVE-2022-29865HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

  • CVE-2022-29862HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

  • CVE-2021-27432HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.

  • CVE-2022-33916HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.01

    OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.

  • CVE-2024-42513MedFeb 10, 2025
    risk 0.34cvss 5.3epss 0.01

    Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.