A vulnerability in OPC Foundation UA .NET Standard allows remote, unauthenticated attackers to exhaust server resources by sending a large number of OPC UA ConditionRefresh requests. The server fails to properly limit or manage these requests, leading to resource exhaustion and a denial-of-service condition. This vulnerability is tracked as ZDI-CAN-20505.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a complete standalone ICS/OT challenge module centered on an OPC UA authentication bypass modeled on CVE-2023-27321/CWE-295. The core vulnerable service is opcua_challenge/gateway.py, a Python asyncua-based OPC UA server that monkey-patches InternalSession.create_session to capture the client-supplied CreateSession ApplicationUri, stores active session URIs, and authorizes privileged action solely by checking whether the session URI contains the configured authorized pattern. The deliberate flaw is in ChallengeUserManager.get_user() and check_authorization(): the server accepts client certificates for channel setup but never validates that the certificate SAN URI matches the session ApplicationUri. The exploit capability is implemented in two Python clients: exploit.py (full CLI attacker tool with argument parsing, recon mode, configurable host/port/path/certs/URI, and success confirmation) and exploit_simple.py (minimal PoC). Both create an OPC UA client, set client.application_uri to the privileged value urn:cddc:admin:console before connecting, negotiate Basic256Sha256_SignAndEncrypt using the sample client certificate and key, browse to the writable node Control_System/System_Override, and write True. If the spoofed URI matches the configured pattern, gateway.py calls trigger_bypass() from bypass_trigger.py. bypass_trigger.py is the post-exploitation component. It unlocks downstream network access either by deleting iptables DROP rules for configured testbed hosts (192.168.2.3 and 192.168.2.4) on competitor interface eth1, or by reconfiguring VLAN membership/PVID on a TP-Link TL-SG105E switch via the smrt helper. reset_bypass() restores the lock after hold_seconds. This means the exploit’s practical outcome is not code execution on the gateway but temporary network reachability to protected PLC/HMI/testbed assets. Repository structure also includes deployment and support tooling: config.json stores endpoint, namespace, authorized URI, isolation settings, and hints; gen_certs.sh generates the server certificate and a sample client certificate whose SAN is urn:cddc:legitimate:client; install.sh automates installation to /opt/opcua_challenge, dependency setup, config generation, certificate generation, network configuration, and competitor package creation; setup_iptables.sh provides a simpler one-time iptables setup path; README.md and deploy.md document challenge operation and deployment. One sensitive artifact is included directly in the repository: certs/sample_client_key.pem, which is the private key used by the sample client exploit. Overall, this is a real exploit repository rather than a detector. It is operational, network-based, and purpose-built for demonstrating/session-layer identity spoofing against a vulnerable OPC UA gateway, with the end goal of unlocking access to downstream ICS infrastructure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.