OPC Foundation UA-.NETStandard
cpe:2.3:a:opcfoundation:ua_.net_standard_stack:*:*:*:*:*:*:*
- < 1.5.374.158
An authentication bypass vulnerability has been identified in the OPC UA .NET Standard Stack, affecting versions prior to 1.5.374.158. This vulnerability allows unauthorized attackers to bypass application authentication when HTTPS endpoints are enabled and use a security policy other than None.
Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access or actions within the application.
Users can update to version 1.5.374.158 or later to address this vulnerability. If application authentication is required, it must be done with HTTPS certificates. For installations without HTTPS client certificates, user authentication should be relied upon for access control.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.