CVE-2021-40142
published 2021-08-27CVE-2021-40142: In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.56%
83.4th percentile
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opcfoundation | local_discover_server | < 1.04.402.463 | 1.04.402.463 |
| siemens | simatic_net_pc | — | — |
| siemens | simatic_net_pc | — | — |
| siemens | simatic_net_pc | — | — |
| siemens | simatic_net_pc | — | — |
| siemens | simatic_process_historian_opc_ua_server_firmware | < 2022 | 2022 |
| siemens | simatic_process_historian_opc_ua_server_firmware | — | — |
| siemens | telecontrol_server_basic | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5524-cf37-2p8f: In OPC Foundation Local Discovery Server (LDS) before 1
ghsa_unreviewed·2022-05-24
CVE-2021-40142 [HIGH] CWE-119 GHSA-5524-cf37-2p8f: In OPC Foundation Local Discovery Server (LDS) before 1
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
CISA ICS
Siemens Industrial Products (Update C)
cisa_ics·2022-08-11
Siemens Industrial Products (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products (Update C)
Last RevisedDecember 15, 2022
Alert CodeICSA-22-132-12
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: OPC Foundation Local Discovery Server of sev
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-321292.pdfhttps://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-40142.pdfhttps://opcfoundation.org/security-bulletins/https://cert-portal.siemens.com/productcert/pdf/ssa-321292.pdfhttps://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-40142.pdfhttps://opcfoundation.org/security-bulletins/
2021-08-27
Published