CVE-2021-45117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/03/2022
Last modified:
03/09/2022

Description

The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opcfoundation:ua-nodeset:*:*:*:*:*:*:*:* 1.05.01 (excluding)
cpe:2.3:a:siemens:simatic_net_pc:14:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_net_pc:15:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_net_pc:17:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sitop_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:telecontrol_server_basic:3.0:*:*:*:*:*:*:*