Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability.
The specific flaw exists within the ImportCsv method. A crafted XML payload can cause a null pointer dereference. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20495.
References
Link | Resource |
---|---|
https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt | Release Notes |
https://www.zerodayinitiative.com/advisories/ZDI-23-776/ | Third Party Advisory |
https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt | Release Notes |
https://www.zerodayinitiative.com/advisories/ZDI-23-776/ | Third Party Advisory |
Configurations
History
08 Aug 2025, 14:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt - Release Notes | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-23-776/ - Third Party Advisory | |
CPE | cpe:2.3:a:unified-automation:uagateway:*:*:*:*:*:*:*:* | |
First Time |
Unified-automation
Unified-automation uagateway |
21 Nov 2024, 08:02
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt - | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-23-776/ - |
03 May 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-03 02:15
Updated : 2025-08-08 14:16
NVD link : CVE-2023-32171
Mitre link : CVE-2023-32171
CVE.ORG link : CVE-2023-32171
JSON object : View
Products Affected
unified-automation
- uagateway
CWE
CWE-476
NULL Pointer Dereference