VendorsOPCFoundationua_.net_standard_stackall versions
Vulnerabilities

OPCFoundation OPC Foundation UA .NET Standard Stack

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-42512
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
Published 2025-02-10 · Analyzed
8.6EPSS 0.006
CVE-2022-29864
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.
Published 2022-06-16 · Modified
7.5EPSS 0.020
CVE-2021-27432
OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
Published 2021-05-20 · Modified
7.5EPSS 0.020
CVE-2022-29866
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
Published 2022-06-16 · Modified
7.5EPSS 0.017
CVE-2022-29865
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
Published 2022-06-16 · Modified
7.5EPSS 0.017
CVE-2022-29862
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
Published 2022-06-16 · Modified
7.5EPSS 0.016
CVE-2022-29863
OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.
Published 2022-06-16 · Modified
7.5EPSS 0.014
CVE-2022-33916
OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.
Published 2022-08-23 · Modified
7.5EPSS 0.013
CVE-2024-42513
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
Published 2025-02-10 · Analyzed
5.3EPSS 0.006