以下是该漏洞描述的中文翻译: node-opcua 是 TypeScript 和 Node.js 环境下的 OPC UA 实现。在 2.166.0 版本之前,位于 中的 身份验证处理器会对 RSA-OAEP 加密的密码数据块进行解密,但并未验证其末尾字节是否与当前会话的服务器随机数(serverNonce)匹配。未认证的远程攻击者可通过 GetEndpoints 接口获取服务器公钥,并构造一个其小端长度(little-endian length)能产生空密码的数据块,该空密码会被传入 函数,从而危害那些接受空密码的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| node-opcua | node-opcua | < 2.166.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| node-opcua | node-opcua | < 2.166.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet