VYPR
Vendor

Opcfoundation

Products
24
CVEs
31
Across products
48
Status
Private

Products

24

Recent CVEs

31
View all 31 CVEs →
  • CVE-2020-27267CriJan 14, 2021
    risk 0.60cvss 9.1epss 0.05

    KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server…

  • CVE-2017-12070HigJun 14, 2018
    risk 0.57cvss 8.8epss 0.01

    Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.

  • CVE-2017-12069HigAug 30, 2017
    risk 0.54cvss 8.2epss 0.03

    An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1),…

  • CVE-2018-12585HigSep 14, 2018
    risk 0.53cvss 8.2epss 0.02

    An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

  • CVE-2022-44725HigNov 17, 2022
    risk 0.51cvss 7.8epss 0.00

    OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

  • CVE-2017-11672HigJun 13, 2018
    risk 0.51cvss 7.8epss 0.00

    The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opcualds.exe executable path, which might allow local users to gain privileges.

  • CVE-2018-12086HigSep 14, 2018
    risk 0.50cvss 7.5epss 0.12

    Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.

  • CVE-2024-42512HigFeb 10, 2025
    risk 0.49cvss 8.6epss 0.01

    Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.

  • CVE-2023-27321HigMay 7, 2024
    risk 0.49cvss 7.5epss 0.01

    OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required…

  • CVE-2023-32787HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.

  • CVE-2022-29866HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

  • CVE-2022-29864HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

  • CVE-2022-29863HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

  • CVE-2022-29865HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

  • CVE-2022-29862HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

  • CVE-2022-30551HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.

  • CVE-2021-40142HigAug 27, 2021
    risk 0.49cvss 7.5epss 0.03

    In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.

  • CVE-2021-27432HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.

  • CVE-2021-27434HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.

  • CVE-2020-8867HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.03

    This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions.…