CVE-2020-8867
OPC Foundation UA .NET Standard CreateSessionRequest Race Condition Denial-of-Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application. Was ZDI-CAN-10295.
Esta vulnerabilidad permite a atacantes remotos crear una condición de denegación de servicio sobre las instalaciones afectadas de OPC Foundation UA ??.NET Standard versión 1.04.358.30. No es requerida una autenticación para explotar esta vulnerabilidad. El fallo específico existe dentro del manejo de las sesiones. El problema resulta de la falta de un bloqueo apropiado al realizar operaciones sobre un objeto. Un atacante puede aprovechar esta vulnerabilidad para crear una condición de denegación de servicio contra la aplicación. Fue ZDI-CAN-10295.
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-11 CVE Reserved
- 2020-04-16 CVE Published
- 2024-04-29 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-613: Insufficient Session Expiration
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-20-536 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opcfoundation Search vendor "Opcfoundation" | Unified Architecture .net-standard Search vendor "Opcfoundation" for product "Unified Architecture .net-standard" | <= 1.04.358.30 Search vendor "Opcfoundation" for product "Unified Architecture .net-standard" and version " <= 1.04.358.30" | - |
Affected
|