CVE-2022-30551
Prosys OPC UA SDK for Java OPC UA Messages Resource Exhaustion Denial-of-Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.
OPC UA Legacy Java Stack versión 01-04-2022, permite a un atacante remoto causar que un servidor deje de procesar mensajes mediante el envío de mensajes diseñados que agotan los recursos disponibles
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Prosys OPC UA SDK for Java. Authentication is not required to exploit this vulnerability.
The specific flaw exists within handling of OPC UA messages. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-11 CVE Reserved
- 2022-05-20 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/OPCFoundation/UA-Java-Legacy | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-30551.pdf | 2022-06-01 |
URL | Date | SRC |
---|---|---|
https://opcfoundation.org | 2022-06-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opcfoundation Search vendor "Opcfoundation" | Ua-java Search vendor "Opcfoundation" for product "Ua-java" | 2022-04-01 Search vendor "Opcfoundation" for product "Ua-java" and version "2022-04-01" | - |
Affected
|