OPC Foundation UA-.NETStandard
cpe:2.3:a:opcfoundation:ua_.net_standard_stack:*:*:*:*:*:*:*
- < 1.5.374.158
An authentication bypass vulnerability has been identified in the OPC UA .NET Standard Stack, affecting versions prior to 1.5.374.158. When the deprecated Basic128Rsa15 security policy is enabled, an unauthorized attacker can exploit this vulnerability to bypass application authentication. Although Basic128Rsa15 is disabled by default, this vulnerability could be a concern for applications that have explicitly enabled it.
Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access or actions within the application.
To address this vulnerability, users should disable the Basic128Rsa15 security policy. The OPC UA .NET Standard Stack has been updated to version 1.5.374.158 to resolve this issue.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.