Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Denial of Service (DoS)
Vulnerability Description
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
N/A
Vulnerability Title
node-opcua 安全漏洞
Vulnerability Description
node-opcua是法国Sterfive SAS开源的一个完全用 Typescript 为 NodeJS 编写的 OPC UA 堆栈的实现。 node-opcua 2.74.0之前版本存在安全漏洞,该漏洞源于当请求的内存分配超过 v8 的内存限制时,通过发送带有特殊 OPC UA NodeID 的特制 OPC UA 消息容易受到拒绝服务 (DoS) 的攻击。
CVSS Information
N/A
Vulnerability Type
N/A