7.5

CVE-2022-25304

Denial of Service (DoS)

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asyncua ProjectAsyncua SwPlatformpython
Opcua ProjectOpcua SwPlatformpython
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.683
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Snyk 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://github.com/FreeOpcUa/python-opcua/issues/1466
Third Party Advisory
Issue Tracking
https://security.snyk.io/vuln/SNYK-PYTHON-ASYNCUA-2988731
Third Party Advisory
https://security.snyk.io/vuln/SNYK-PYTHON-OPCUA-2988730
Third Party Advisory