CVE-2021-45117
MEDIUMOPC Foundation UA-NodeSet < 1.05.01 - NULL Pointer Dereference
Title source: llmDescription
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=qv-RBdCaV4k
Patch, Vendor Advisory x_refsource_misc
https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-45117.pdf
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-285795.pdf
Scores
CVSS v3
6.5
EPSS
0.0052
EPSS Percentile
67.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (7)
opcfoundation/ua-nodeset
< 1.05.01
siemens/simatic_net_pc
14
siemens/simatic_net_pc
15
siemens/simatic_net_pc
16
siemens/simatic_net_pc
17
siemens/sitop_manager
siemens/telecontrol_server_basic
3.0
Published
Mar 21, 2022
Tracked Since
Feb 18, 2026