Uncontrolled Recursion in OPC UA .NET Legacy and OPC UA .NET Standard - CVE-2021-27432
Published: May 14, 2021
Vulnerability identifier: #VU53244
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27432
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an uncontrolled recursion. A remote attacker can cause a denial of service condition on the target system.
Affected software
OPC UA .NET Legacy
OPC UA .NET Standard
MobileHMI
Energy AnalytiX
GENESIS64
MC Works64
Hyper Historian
OPC UA .NET Standard
MobileHMI
Energy AnalytiX
GENESIS64
MC Works64
Hyper Historian
How to mitigate CVE-2021-27432
Install updates from vendor's website.
OPC UA .NET Standard - update to 1.4.365.48
GENESIS64 - update to 10.97.1
GENESIS64 - update to 10.97.1