RSS   Vulnerabilities for 'Ua-.netstandard'   RSS

2021-02-16
 
CVE-2020-29457

CWE-295
 

 
A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 allows attackers to establish a connection using invalid certificates.

 
2020-03-16
 
CVE-2019-19135

CWE-522
 

 
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.

 
2018-06-13
 
CVE-2018-7559

CWE-320
 

 
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed bad UserIdentityTokens as part of an oracle attack.

 

 >>> Vendor: Opcfoundation 11 Products
Local discovery server
Ua-.net-legacy
Ua-.netstandard
Ua-java
Unified architecture-.net-legacy
Unified architecture-java
Unified architecture .net-standard
Unified architecture ansic
Netstandard.opc.ua
Local discover server
Ua-nodeset


Copyright 2024, cxsecurity.com

 

Back to Top