Записи opcfoundation
28 опубликованных записей вендора opcfoundation.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 64,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption5
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-295 Improper Certificate Validation2
- CWE-20 Improper Input Validation2
- CWE-208 Observable Timing Discrepancy1
- CWE-305 Authentication Bypass by Primary Weakness1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
28 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2017-12070Эксплойта нет | Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.opcfoundation · ua-.net-legacy · CWE-20 | Высокая8,8 | — | 1,0 % | 14 июн. 2018 г. |
34Наблюдать | CVE-2018-12086Proof of concept | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.opcfoundation · unified architecture-.net-legacy · CWE-787 | Высокая7,5 | — | 11,8 % | 14 сент. 2018 г. |
34Наблюдать | CVE-2024-42512Эксплойта нет | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication whenopcfoundation · ua .net standard stack · CWE-208 | Высокая8,6 | — | 0,6 % | 10 февр. 2025 г. |
32Наблюдать | CVE-2018-12585Эксплойта нет | An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.opcfoundation · ua-.net-legacy · CWE-611 | Высокая8,2 | — | 1,6 % | 14 сент. 2018 г. |
31Наблюдать | CVE-2020-8867Эксплойта нет | This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standopcfoundation · unified architecture .net-standard · CWE-367 | Высокая7,5 | — | 2,6 % | 22 апр. 2020 г. |
31Наблюдать | CVE-2021-40142Эксплойта нет | In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefullopcfoundation · local discover server · CWE-119 | Высокая7,5 | — | 2,6 % | 27 авг. 2021 г. |
31Наблюдать | CVE-2022-30551Эксплойта нет | OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that opcfoundation · ua-java · CWE-400 | Высокая7,5 | — | 2,1 % | 20 мая 2022 г. |
31Наблюдать | CVE-2022-29864Эксплойта нет | OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontroopcfoundation · ua .net standard stack · CWE-400 | Высокая7,5 | — | 2,0 % | 16 июн. 2022 г. |
31Наблюдать | CVE-2021-27432Эксплойта нет | OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may aopcfoundation · ua-.net-legacy · CWE-674 | Высокая7,5 | — | 2,0 % | 20 мая 2021 г. |
31Наблюдать | CVE-2022-29866Эксплойта нет | OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggersopcfoundation · ua .net standard stack · CWE-400 | Высокая7,5 | — | 1,7 % | 16 июн. 2022 г. |
31Наблюдать | CVE-2022-29865Эксплойта нет | OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.opcfoundation · ua .net standard stack · CWE-287 | Высокая7,5 | — | 1,7 % | 16 июн. 2022 г. |
31Наблюдать | CVE-2017-11672Эксплойта нет | The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opopcfoundation · local discovery server · CWE-428 | Высокая7,8 | — | 0,3 % | 13 июн. 2018 г. |
31Наблюдать | CVE-2022-44725Эксплойта нет | OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file.opcfoundation · local discovery server · CWE-732 | Высокая7,8 | — | 0,2 % | 17 нояб. 2022 г. |
30Наблюдать | CVE-2022-29862Эксплойта нет | An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.opcfoundation · ua .net standard stack · CWE-835 | Высокая7,5 | — | 1,6 % | 16 июн. 2022 г. |
30Наблюдать | CVE-2022-29863Эксплойта нет | OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.opcfoundation · ua .net standard stack · CWE-770 | Высокая7,5 | — | 1,4 % | 16 июн. 2022 г. |
30Наблюдать | CVE-2022-33916Эксплойта нет | OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.opcfoundation · ua .net standard stack | Высокая7,5 | — | 1,3 % | 22 авг. 2022 г. |
30Наблюдать | CVE-2023-32787Эксплойта нет | The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption soopcfoundation · ua java legacy · CWE-400 | Высокая7,5 | — | 1,2 % | 15 мая 2023 г. |
30Наблюдать | CVE-2023-27321Эксплойта нет | OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerabilityopcfoundation · ua-.netstandard · CWE-400 | Высокая7,5 | — | 1,0 % | 7 мая 2024 г. |
30Наблюдать | CVE-2024-33862Эксплойта нет | A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers toCWE-770 | Высокая7,5 | — | 0,6 % | 5 июл. 2024 г. |
29Наблюдать | CVE-2019-19135Эксплойта нет | In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Oopcfoundation · netstandard.opc.ua · CWE-330 | Высокая7,4 | — | 1,0 % | 16 мар. 2020 г. |
26Наблюдать | CVE-2021-45117Эксплойта нет | The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases.opcfoundation · ua-nodeset · CWE-476 | Средняя6,5 | — | 1,4 % | 21 мар. 2022 г. |
26Наблюдать | CVE-2017-17443Эксплойта нет | OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to opcfoundation · local discovery server · CWE-20 | Средняя6,5 | — | 0,9 % | 13 июн. 2018 г. |
21Наблюдать | CVE-2018-7559Эксплойта нет | An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sampopcfoundation · ua-.net-legacy · CWE-320 | Средняя5,3 | — | 1,2 % | 13 июн. 2018 г. |
21Наблюдать | CVE-2023-31048Эксплойта нет | The OPC UA .NET Standard Reference Server before 1.4.371.86.opcfoundation · ua-.netstandard · CWE-209 | Средняя5,3 | — | 0,8 % | 12 дек. 2023 г. |
21Наблюдать | CVE-2024-42513Эксплойта нет | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication whenopcfoundation · ua .net standard stack · CWE-305 | Средняя5,3 | — | 0,6 % | 10 февр. 2025 г. |
- CVE-2017-1207035Наблюдать
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %opcfoundation · ua-.net-legacy14 июн. 2018 г.
- CVE-2018-1208634Наблюдать
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %opcfoundation · unified architecture-.net-legacy14 сент. 2018 г.
- CVE-2024-4251234Наблюдать
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %opcfoundation · ua .net standard stack10 февр. 2025 г.
- CVE-2018-1258532Наблюдать
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
ВысокаяCVSS 8,2Эксплойта нетEPSS 2 %opcfoundation · ua-.net-legacy14 сент. 2018 г.
- CVE-2020-886731Наблюдать
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Stand
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %opcfoundation · unified architecture .net-standard22 апр. 2020 г.
- CVE-2021-4014231Наблюдать
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefull
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %opcfoundation · local discover server27 авг. 2021 г.
- CVE-2022-3055131Наблюдать
OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opcfoundation · ua-java20 мая 2022 г.
- CVE-2022-2986431Наблюдать
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontro
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opcfoundation · ua .net standard stack16 июн. 2022 г.
- CVE-2021-2743231Наблюдать
OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opcfoundation · ua-.net-legacy20 мая 2021 г.
- CVE-2022-2986631Наблюдать
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opcfoundation · ua .net standard stack16 июн. 2022 г.
- CVE-2022-2986531Наблюдать
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opcfoundation · ua .net standard stack16 июн. 2022 г.
- CVE-2017-1167231Наблюдать
The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the op
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %opcfoundation · local discovery server13 июн. 2018 г.
- CVE-2022-4472531Наблюдать
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %opcfoundation · local discovery server17 нояб. 2022 г.
- CVE-2022-2986230Наблюдать
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opcfoundation · ua .net standard stack16 июн. 2022 г.
- CVE-2022-2986330Наблюдать
OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opcfoundation · ua .net standard stack16 июн. 2022 г.
- CVE-2022-3391630Наблюдать
OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opcfoundation · ua .net standard stack22 авг. 2022 г.
- CVE-2023-3278730Наблюдать
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opcfoundation · ua java legacy15 мая 2023 г.
- CVE-2023-2732130Наблюдать
OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opcfoundation · ua-.netstandard7 мая 2024 г.
- CVE-2024-3386230Наблюдать
A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %5 июл. 2024 г.
- CVE-2019-1913529Наблюдать
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.O
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %opcfoundation · netstandard.opc.ua16 мар. 2020 г.
- CVE-2021-4511726Наблюдать
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opcfoundation · ua-nodeset21 мар. 2022 г.
- CVE-2017-1744326Наблюдать
OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opcfoundation · local discovery server13 июн. 2018 г.
- CVE-2018-755921Наблюдать
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Samp
СредняяCVSS 5,3Эксплойта нетEPSS 1 %opcfoundation · ua-.net-legacy13 июн. 2018 г.
- CVE-2023-3104821Наблюдать
The OPC UA .NET Standard Reference Server before 1.4.371.86.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %opcfoundation · ua-.netstandard12 дек. 2023 г.
- CVE-2024-4251321Наблюдать
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when
СредняяCVSS 5,3Эксплойта нетEPSS 1 %opcfoundation · ua .net standard stack10 февр. 2025 г.