CVE-2021-42262

MEDIUM

Softing OPC UA C++ SDK 5.56.0-5.69.0 - Denial of Service via Invalid XML Element in Type Dictionary

Title source: llm
STIX 2.1

Description

An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.

Scores

CVSS v3 6.5
EPSS 0.0080
EPSS Percentile 51.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (3)
softing/datafeed_opc_suite < 5.19
softing/opc_ua_c\+\+_software_development_kit 5.56.0 - 5.70.0
softing/secure_integration_server < 1.22
Published Mar 11, 2022
Tracked Since Feb 18, 2026