Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Opcfoundation

34 known vulnerabilities

19
HIGH
7
MEDIUM

Top Products

ua .net standard stack 9 ua-.netstandard 6 ua-.net-legacy 5 local discovery server 3 ua-java 2 unified architecture .net-standard 2 ua java legacy 1 ua-nodeset 1 local discover server 1 netstandard.opc.ua 1
26 CVEs
5.3
CVE-2024-42513

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application

8.6
CVE-2024-42512

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application

7.5
CVE-2023-27321

OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability

5.3
CVE-2023-31048

The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may

7.5
CVE-2023-32787

The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled res

7.8
CVE-2022-44725

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. Th

7.5
CVE-2022-33916

OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive inf

7.5
CVE-2022-29866

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted r

7.5
CVE-2022-29864

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages t

7.5
CVE-2022-29863

OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessiv

7.5
CVE-2022-29865

OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake cred

7.5
CVE-2022-29862

An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a

7.5
CVE-2022-30551

OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending cr

6.5
CVE-2021-45117

The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointe

7.5
CVE-2021-40142

In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS)

7.5
CVE-2021-27432

OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled re

4.4
CVE-2020-29457

A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establi

7.5
CVE-2020-8867

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foun

7.4
CVE-2019-19135

In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoun

5.3
CVE-2018-12087

Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attacker

8.2
CVE-2018-12585

An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

7.5
CVE-2018-12086

Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured req

8.8
CVE-2017-12070

Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.

5.3
CVE-2018-7559

An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET L

6.5
CVE-2017-17443

OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that

7.8
CVE-2017-11672

The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double

Frequently Asked Questions

How many CVEs affect Opcfoundation?

Opcfoundation has 34 CVE records in our database, including 0 critical and 25 high severity vulnerabilities.

What are the most severe Opcfoundation vulnerabilities?

Opcfoundation has 0 critical severity (CVSS 9.0+) and 25 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Opcfoundation vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Opcfoundation products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Opcfoundation Vulnerabilities

CyberStrike scans your infrastructure for Opcfoundation vulnerabilities and provides real-time remediation guidance.

Get Started