ZeroHour

CVE-2022-24375

CVSS 3.1
7.5 high
EPSS
2%p76
Published
()
Modified
Description

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

Vendors
node-opcua project
Products
node-opcua
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.