Lucene search

K
cveMitreCVE-2023-32787
HistoryMay 15, 2023 - 3:15 p.m.

CVE-2023-32787

2023-05-1515:15:12
CWE-400
mitre
web.nvd.nist.gov
35
cve-2023-32787
opc ua
legacy java stack
nvd
security vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.2%

The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.

Affected configurations

Nvd
Node
opcfoundationua_java_legacyRange<2023-04-28
Node
prosysopcua_historianRange<1.2.0
OR
prosysopcua_modbus_serverRange<1.4.20
OR
prosysopcua_simulation_serverRange<5.4.2
VendorProductVersionCPE
opcfoundationua_java_legacy*cpe:2.3:a:opcfoundation:ua_java_legacy:*:*:*:*:*:*:*:*
prosysopcua_historian*cpe:2.3:a:prosysopc:ua_historian:*:*:*:*:*:*:*:*
prosysopcua_modbus_server*cpe:2.3:a:prosysopc:ua_modbus_server:*:*:*:*:*:*:*:*
prosysopcua_simulation_server*cpe:2.3:a:prosysopc:ua_simulation_server:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

57.2%

Related for CVE-2023-32787