CVE-2022-29866
Uncontrolled Resource Consumption in OPCFoundation.NetStandard.Opc.Ua.Core
EPSS 0.80%
Description
A vulnerability was discovered in the OPC UA .NET Standard Stack that allows a malicious client to trigger a stack overflow exception in a server that exposes an HTTPS endpoint.
How to fix CVE-2022-29866
To remediate CVE-2022-29866, upgrade the affected package to a fixed version below.
- NuGet/OPCFoundation.NetStandard.Opc.Ua.Core—upgrade to 1.4.368.58 or later
Is CVE-2022-29866 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.4.368.58