PT-2024-20726 · Softing · Softing Uatoolkit Embedded

CVE-2024-25075

·

Published

2024-04-02

·

Updated

2024-04-03

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Softing uaToolkit Embedded versions prior to 1.41.1
Description An issue was discovered in Softing uaToolkit Embedded. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is mishandled, leading to memory consumption. When that happens often enough, the device will be out of memory, i.e., a denial of service.
Recommendations For versions prior to 1.41.1, update to version 1.41.1 or later to resolve the issue. As a temporary workaround, consider restricting the creation of subscriptions with very low MaxNotificationPerPublish parameters to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-25075

Affected Products

Softing Uatoolkit Embedded