Buffer overflow in UA-LDS - CVE-2021-40142
Published: May 17, 2022
Vulnerability identifier: #VU63312
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40142
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote attacker can send a specially crafted message, trigger memory corruption and cause a denial of service condition on the target system.
Affected software
UA-LDS
SIMATIC Process Historian OPC UA Server
SIMATIC WinCC Runtime Professional
Siemens SIMATIC WinCC
SIMATIC WinCC Unified Scada Runtime
SIMATIC NET PC Software
TeleControl Server Basic
SIMATIC Process Historian OPC UA Server
SIMATIC WinCC Runtime Professional
Siemens SIMATIC WinCC
SIMATIC WinCC Unified Scada Runtime
SIMATIC NET PC Software
TeleControl Server Basic
How to mitigate CVE-2021-40142
Install updates from vendor's website.
UA-LDS - update to 1.04.402.463
SIMATIC NET PC Software - addressed in versions 14 SP1 Update 14, 17 SP1
SIMATIC Process Historian OPC UA Server - update to 14 SP1 Update 14
SIMATIC NET PC Software - addressed in versions 14 SP1 Update 14, 17 SP1
SIMATIC Process Historian OPC UA Server - update to 14 SP1 Update 14