CVE-2021-40142
7.5 HIGHIn OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending caref...
Published: 2021-08-27 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-119
Affected products
| Vendor | Product |
|---|---|
| opcfoundation | local_discover_server, simatic_net_pc, simatic_process_historian_opc_ua_server_firmware |
| siemens | local_discover_server, simatic_net_pc, simatic_process_historian_opc_ua_server_firmware |
Description
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-40142
- [Patch]https://cert-portal.siemens.com/productcert/pdf/ssa-321292.pdf
- [Patch]https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-40142.pdf
- [Vendor advisory]https://opcfoundation.org/security-bulletins/
- [Patch]https://cert-portal.siemens.com/productcert/pdf/ssa-321292.pdf
- [Patch]https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-40142.pdf
- [Vendor advisory]https://opcfoundation.org/security-bulletins/
Related CVEs
Same vendor
- CVE-2026-46749 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6) (7.5 HIGH)
- CVE-2026-46748 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6) (8.8 HIGH)
- CVE-2026-46747 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6) (4.3 MEDIUM)
- CVE-2026-46746 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6) (8.8 HIGH)
- CVE-2026-0257 — Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker ... (9.1 CRITICAL)
Same CWE
- CVE-2026-12330 — Incorrect boundary conditions in the Internationalization component (5.4 MEDIUM)
- CVE-2026-12329 — Memory safety bug fixed in Thunderbird ESR 140.12 (5.3 MEDIUM)
- CVE-2026-12327 — Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151 (7.3 HIGH)
- CVE-2026-12326 — Memory safety bugs present in Firefox 151 and Thunderbird 151 (7.3 HIGH)
- CVE-2026-12318 — Incorrect boundary conditions in the Libraries component in NSS (7.3 HIGH)