An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Datafeed_opc_suite | Softing | * | 5.18 (excluding) |
Edgeconnector | Softing | * | 2.31 (including) |
Opc | Softing | * | 5.66 (excluding) |
Secure_integration_server | Softing | * | 1.22 (including) |
Th_scope | Softing | 3.5 (including) | * |
Uagates | Softing | * | 1.73 (excluding) |
Uatoolkit_embedded | Softing | * | 1.40 (excluding) |