CVE Tools

Opcfoundation

11 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.

Opcfoundation CVEs per month

Jun 2018 to Jun 2022. Point at a month, or focus the strip and use the arrow keys.
Opcfoundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0640
2018-07null or fewer
2018-08null or fewer
2018-0920
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-0650

Products

The products that kept showing up in Opcfoundation's monthly top three, with their CVEs summed over those months.

  1. Ua .net Standard Stack51 month
  2. Ua-.net-legacy32 months
  3. Local Discovery Server21 month
  4. Ua-.netstandard11 month
  5. Ua-java11 month
  6. Unified Architecture Ansic11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Opcfoundation.

  1. CVE-2024-42512Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.8.6
  2. CVE-2024-42513Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.5.3
  3. CVE-2023-27321OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability7.5
  4. CVE-2023-31048The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.5.3
  5. CVE-2023-32787The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.7.5
  6. CVE-2022-44725OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (run...7.8
  7. CVE-2022-33916OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.7.5
  8. CVE-2022-29866OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.7.5
  9. CVE-2022-29863OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.7.5
  10. CVE-2022-29864OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.7.5
  11. CVE-2022-29862An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.7.5
  12. CVE-2022-29865OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.7.5
  13. CVE-2022-30551OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.7.5
  14. CVE-2021-45117The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.6.5
  15. CVE-2021-40142In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Locati...7.5

The record

Peak rank
#94 in Jun 2018
Busiest month shown
Jun 2022, 5 CVEs
Months with a KEV entry
0 since Jun 2018
Monthly snapshots
3 since 2018
Opcfoundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store