node-opcua 是面向 TypeScript 和 Node.js 的 OPC UA 实现。在 node-opcua-client 2.145.0 之前的版本中,位于 文件中的内部方法 直接分配了未经净化的字段名,并允许通过 路径修改 。成功利用此漏洞需要应用程序向 暴露由攻击者控制的事件字段,可能导致拒绝服务(DoS)或应用程序逻辑损坏。该漏洞已在 2.145.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| node-opcua | node-opcua | < 2.145.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet