CVE-2018-7559
13.06.2018, 18:29
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed bad UserIdentityTokens as part of an oracle attack.Enginsight
Vendor | Product | Version |
---|---|---|
opcfoundation | ua-.net-legacy | 𝑥 ≤ 1.03.342 |
opcfoundation | ua-.netstandard | 𝑥 ≤ 1.03.352.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References