logo

OPC UA Deep Dive Series (Part 7): Practical Denial of Service Attacks

ID: 0d941af6-5452-5e41-af7d-4f0c80cf120e

STIX ID: report--0d941af6-5452-5e41-af7d-4f0c80cf120e

Feed Name: Claroty Team82

Threat Score
60/100

Date Published: 2023-11-07

Date Updated: 2026-04-17

...
...

In Part 7 of Team82's OPC UA Deep Dive Series, the authors detail denial-of-service attack concepts against OPC UA servers — specifically chunk flooding (CVE-2023-32787) and unlimited method-call/resource exhaustion (CVE-2023-27321) — describing how unbounded message chunks and unrestricted ConditionRefresh calls can exhaust memory and crash servers, the operational impacts on industrial environments, and that the findings were responsibly disclosed and patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.