CVE-2022-25761

The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 70.27%
Affected Products (NVD)
VendorProductVersion
open62541open62541
𝑥
< 1.2.5
open62541open62541
1.3:rc1
open62541open62541
1.3:rc2
open62541open62541
1.3:rc2-ef
open62541open62541
1.3:rc2-ef2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
open62541
forky
1.4.18-1
fixed
sid
1.4.18-1
fixed
trixie
1.4.11.1-1
fixed