CVE-2021-40872

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/11/2021
Last modified:
16/11/2021

Description

An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:softing:smartlink_hw-dp:*:*:*:*:*:*:*:* 1.10 (including)
cpe:2.3:a:softing:uatoolkit_embedded:*:*:*:*:*:*:*:* 1.40 (excluding)