CVE-2024-5000

An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
Configurations

No configuration.

History

21 Nov 2024, 09:46

Type Values Removed Values Added
References () https://cert.vde.com/en/advisories/VDE-2024-026 - () https://cert.vde.com/en/advisories/VDE-2024-026 -
References () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=18355&token=e3e5a937ce72602bec39718ddc2f4ba6d983ccd1&download= - () https://customers.codesys.com/index.php?eID=dumpFile&t=f&f=18355&token=e3e5a937ce72602bec39718ddc2f4ba6d983ccd1&download= -

04 Jun 2024, 16:57

Type Values Removed Values Added
Summary
  • (es) Un atacante remoto no autenticado puede utilizar un cliente OPC UA malicioso para enviar una solicitud manipulada a los productos CODESYS afectados, lo que puede provocar un DoS debido a un cálculo incorrecto del tamaño del búfer.

04 Jun 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-04 09:15

Updated : 2024-11-21 09:46


NVD link : CVE-2024-5000

Mitre link : CVE-2024-5000

CVE.ORG link : CVE-2024-5000


JSON object : View

Products Affected

No product.

CWE
CWE-131

Incorrect Calculation of Buffer Size