VDB

GHSA-qv5f-57gw-vx3h

GHSA-qv5f-57gw-vx3h PUBLISHED CVSS 8.600000381469727 HIGH

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.

Risk Scores

CVSS v3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected Products

VendorProductVersions
csaf_ncscnlSCALANCE MUM856-1 (A1)
csaf_ncscnlSiPass integrated AC5102, SiPass integrated ACC-AP
csaf_ncscnlSCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1)
csaf_ncscnlSCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2)
csaf_certbundV19 Update 4
csaf_cisaSIMATIC WinCC Unified V19
csaf_ncscnlSIMATIC IPC847E
csaf_cisaSIMATIC IPC DiagMonitor
csaf_ncscnlRUGGEDCOM RM1224 LTE(4G) NAM
csaf_ncscnlSCALANCE M876-3 (ROK)
csaf_ncscnlvers:unknown/<v2404.0010
csaf_ncscnlSCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2)
csaf_siemensSIMATIC Energy Manager PRO V7.5
csaf_ncscnlSCALANCE S615 EEC LAN-Router
csaf_ncscnlSCALANCE M816-1 ADSL-Router family
csaf_cisaSIMATIC WinCC Unified V18
csaf_ncscnlSCALANCE M876-3
csaf_ncscnlSIMATIC Field PG M6
csaf_ncscnlTeamcenter Visualization V2406
csaf_certbundOPC Foundation OPC UA .NET Standard Stack 1.5.374.158

…and 111 more

Timeline

  • CVE Published
  • Mar 2, 2026 Security Advisory
  • Mar 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›