Unified Automation provides OPC UA (OLE for Process Control Unified Architecture) implementation libraries and gateway products that enable industrial automation and control systems to interoperate across enterprise and operational-technology environments. The vendor's vulnerability footprint centers on its UAGateway and OPC UA SDK offerings across both C++ and .NET platforms, reflecting the integration demands of protocol translation and industrial middleware. Weakness patterns and live severity or exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unified Automation over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32174CRITICAL Unified Automation UaGateway NodeManagerOpcUa Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected i | May 3, 2024 | 9.1 | 25 | NO | NO |
CVE-2022-37013HIGH This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rol | Mar 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-37012HIGH This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537. Authentication | Mar 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-27434HIGH Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontr | May 20, 2021 | 7.5 | 23 | NO | NO |
CVE-2023-41185HIGH Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service conditio | May 3, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-32172MEDIUM Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on aff | May 3, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-32171MEDIUM Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condit | May 3, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-32173MEDIUM Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected | May 3, 2024 | 5.8 | 18 | NO | NO |
CVE-2023-32170MEDIUM Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condi | May 3, 2024 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unified Automation.
Media articles that mention a CVE ID that affects a product developed by Unified Automation — matched by CVE ID, not by vendor name.