CVE-2021-40871

An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a OPC/UA client. The client process may crash unexpectedly because of a wrong type cast, and must be restarted.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:softing:datafeed_opc_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:opc:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:secure_integration_server:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:th_scope:*:*:*:*:*:*:*:*

History

16 Nov 2021, 14:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CPE cpe:2.3:a:softing:th_scope:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:secure_integration_server:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:datafeed_opc_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:softing:opc:*:*:*:*:*:*:*:*
CWE CWE-843
References (MISC) https://industrial.softing.com/fileadmin/sof-files/pdf/ia/support/Security_Bulletin-CVE-2021-40871.pdf - (MISC) https://industrial.softing.com/fileadmin/sof-files/pdf/ia/support/Security_Bulletin-CVE-2021-40871.pdf - Vendor Advisory
References (MISC) https://industrial.softing.com/ - (MISC) https://industrial.softing.com/ - Vendor Advisory

10 Nov 2021, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-10 23:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-40871

Mitre link : CVE-2021-40871

CVE.ORG link : CVE-2021-40871


JSON object : View

Products Affected

softing

  • th_scope
  • datafeed_opc_suite
  • opc
  • secure_integration_server
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')