Vulnerabilities > CVE-2023-26151 - Infinite Loop vulnerability in Freeopcua Opcua-Asyncio
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://gist.github.com/artfire52/1540b234350795e0ecb4d672608dbec8
- https://github.com/FreeOpcUa/opcua-asyncio/releases/tag/v0.9.96
- https://security.snyk.io/vuln/SNYK-PYTHON-ASYNCUA-5673709
- https://github.com/FreeOpcUa/opcua-asyncio/issues/1013
- https://github.com/FreeOpcUa/opcua-asyncio/pull/1039
- https://github.com/FreeOpcUa/opcua-asyncio/commit/f6603daa34a93a658f0e176cb0b9ee5a6643b262