Resource exhaustion in Prosys OPC products - CVE-2023-32787
Published: June 1, 2023
Vulnerability identifier: #VU76736
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32787
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the handling of OpenSecureChannel messages. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
UA Simulation Server
UA SDK for Java
UA Historian
UA Modbus Server
UA SDK for Java
UA Historian
UA Modbus Server
How to mitigate CVE-2023-32787
Install updates from vendor's website.
UA Simulation Server - update to 5.4.4
UA SDK for Java - update to 4.10.4
UA Historian - update to 1.2.2
UA Modbus Server - update to 1.4.22
UA SDK for Java - update to 4.10.4
UA Historian - update to 1.2.2
UA Modbus Server - update to 1.4.22
External References
- https://github.com/OPCFoundation/UA-Java-Legacy/commit/6f176f2b445a27c157f1a32f225accc9ce8873c0
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2023-32787.pdf
- https://github.com/OPCFoundation/UA-Java-Legacy
- https://www.zerodayinitiative.com/advisories/ZDI-23-778/
- https://www.prosysopc.com/blog/pwn2own-2023-resource-exhaustion-exploit/