CVE: CVE-2022-25302

Export to Word

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed casting when unvalidated data is forwarded to boost::get function in OpcUaNodeIdBase.h. Exploiting this vulnerability is possible when sending a specifically crafted OPC UA message with a special encoded NodeId.

Threat-Mapped Scoring

Score: 1.5

Priority: P4 - Informational (Low)

EPSS

Score: 0.00092
Percentile: 0.26919

CVSS Scoring

CVSS v3.1 Score: 7.5

Severity: HIGH

Affected Products

← Back to Home