Impact
The CVE describes a heap use‑after‑free in the GDS PushManagement certificate update workflow of the open62541 OPC UA library when the UA_ENABLE_GDS_PUSHMANAGEMENT option is enabled. Exploiting this flaw allows a remote attacker to trigger a denial‑of‑service condition by causing the server to crash or reset during the certificate update process.
Affected Systems
Any installation of open62541 that is compiled with UA_ENABLE_GDS_PUSHMANAGEMENT enabled, such as embedded or custom OPC UA servers, is affected. The specific affected versions are not listed in the provided data.
Risk and Exploitability
A remote attacker can invoke the vulnerable certificate update routine over the network, leading to a crash. The vulnerability is a heap use‑after‑free (CWE‑825) and a resource exhaustion flaw (CWE‑400) with a CVSS score of 7.5. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation yet the impact remains significant for exposed servers.
OpenCVE Enrichment