CRITICAL🇵🇱 Wersja polska

CVE-2023-32174

CVSS 9.1v3.0pub. 2024-05-03upd. 2025-08-08

Unified Automation UaGateway NodeManagerOpcUa Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default configuration. The specific flaw exists within the handling of NodeManagerOpcUa objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-20577.

🤖 AI Analysis
How it works

The vulnerability results from lack of verification of the existence of the NodeManagerOpcUa object before performing operations on this object, which leads to a classic use-after-free error. An attacker can craft an appropriate request that references an already freed memory area. In the default configuration of the product, authentication is required to exploit the vulnerability. Successful exploitation of the error allows an attacker to take control of the program execution flow and execute malicious code.

Impact

An attacker can execute arbitrary code in the context of the SYSTEM account, which means complete takeover of the compromised system, including the ability to install malicious software, steal data, and perform lateral movement in the network.

Mitigation & patch

Update Unified Automation UaGateway to version 1.5.14 or newer according to the information in the vendor documentation (https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt). As an additional measure, it is recommended to restrict network access to the OPC UA interface exclusively to trusted hosts.

Who is affected

Unified Automation UaGateway — versions indicated in the vendor references (changelog available for version 1.5.14 indicates the patched release)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Unified Automation Uagateway

    APP
    Unified-Automation
    < 1.5.14.495
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2023-41185HIGH7.5same product

Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulner...

CVE-2023-32170MEDIUM6.5same product

Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service Vulnerability. This vul...

CVE-2023-32171MEDIUM6.5same product

Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vuln...

CVE-2023-32172MEDIUM6.5same product

Unified Automation UaGateway OPC UA Server Use-After-Free Denial-of-Service Vulnerability. This vulnerability ...

CVE-2023-32173MEDIUM5.8same product

Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allow...