SSA-285795
The OPC UA ANSIC Stack (also called Legacy C-Stack) was reported to crash when an unexpected OPC UA Response message status code was accessed via the synchronous Client API. The vulnerability was found in generated code of the OPC Foundation C-Stack. An unexpected status code in response message will dereference Null pointer leading to crash, ping of death (PoD). This affects a client, but it might also affect a server when it uses OpcUa_ClientApi_RegisterServer (e.g. register at LDS). A specially crafted UA server, or Man in the Middle attacker, can cause the OPC UA application to crash by sending uncertain status code in response message.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SIMATIC HMI Comfort Panels (incl. SIPLUS variants) | |
| Siemens | TeleControl Server Basic V3 | |
| Siemens | SIMATIC NET PC Software V14 | |
| Siemens | SIMATIC NET PC Software V17 | |
| Siemens | SITOP Manager | |
| Siemens | SIMATIC NET PC Software V15 | |
| Siemens | SIMATIC HMI Comfort Outdoor Panels (incl. SIPLUS variants) | |
| Siemens | SIMATIC NET PC Software V16 | |
| Siemens | SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F |
Timeline
- May 10, 2022 CVE Published
- Oct 10, 2023 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-285795.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-285795.html advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-285795.pdf advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-285795.txt advisory
- https://support.industry.siemens.com/cs/ww/en/view/109760607/ patch
- https://support.industry.siemens.com/cs/ww/en/view/109812231/ patch
- https://support.industry.siemens.com/cs/ww/en/view/109746530/ patch
- https://support.industry.siemens.com/cs/ww/en/view/109811815/ patch
- https://support.industry.siemens.com/cs/ww/en/view/109807351/ patch