This vulnerability allows remote attackers to create a denial-of-service condition...
Vulnerability Description
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to create a denial-of-service condition against the application. Was ZDI-CAN-10295.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8867
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Steven Seeley (mr_me) and Chris Anastasio (muffin)
References
Affected Vendor
OPC Foundation
View all reports →