Etienne Rossignon

2 exploits Active since Aug 2022
CVE-2022-24375 WRITEUP HIGH WRITEUP
node-opcua <2.74.0 - DoS
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
CVSS 7.5
CVE-2022-25231 WRITEUP HIGH WRITEUP
Node-opcua < 2.74.0 - Resource Allocation Without Limits
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA message with a special OPC UA NodeID, when the requested memory allocation exceeds the v8’s memory limit.
CVSS 7.5