OPC UA Deep Dive Series (Part 7): Practical Denial of Service Attacks
ID: 0d941af6-5452-5e41-af7d-4f0c80cf120e
STIX ID: report--0d941af6-5452-5e41-af7d-4f0c80cf120e
Feed Name: Claroty Team82
Threat Score
In Part 7 of Team82's OPC UA Deep Dive Series, the authors detail denial-of-service attack concepts against OPC UA servers — specifically chunk flooding (CVE-2023-32787) and unlimited method-call/resource exhaustion (CVE-2023-27321) — describing how unbounded message chunks and unrestricted ConditionRefresh calls can exhaust memory and crash servers, the operational impacts on industrial environments, and that the findings were responsibly disclosed and patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
