CVE-2021-40872 affects Softing Industrial Automation uaToolkit Embedded versions prior to 1.40, including softing smartlink_hw-dp. This vulnerability allows remote attackers to trigger a denial of service (DoS) or bypass security checks to log in as an anonymous user by sending specially crafted OPC/UA messages, leading to an unexpected server crash. With a CVSS score of 7.5 (HIGH), it is easily exploitable over the network with low attack complexity, resulting in high availability impact. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.10CPE matchmatch criteria | cpe:2.3:a:softing:smartlink_hw-dp:*:*:*:*:*:*:*:* | ||
< 1.40CPE matchmatch criteria | cpe:2.3:a:softing:uatoolkit_embedded:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.