SCA: security update for OPCFoundation.NetStandard.Opc.Ua.Server (GHSA-vpf7-r2fv-75m9)

high Tenable Cloud Security Plugin ID 419454

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This
vulnerability allows remote attackers to create a denial-of-service condition on affected installations of
OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability. The
specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of
requests, an attacker can consume all available resources on the server. An attacker can leverage this
vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20505. (CVE-2023-27321)

See Also

https://github.com/advisories/GHSA-vpf7-r2fv-75m9

Plugin Details

Severity: High

ID: 419454

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2023-27321

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/5/2023

Vulnerability Publication Date: 5/5/2023

Reference Information

CVE: CVE-2023-27321

cwe: CWE-400