SSA-858251 PUBLISHED CVSS 7.400000095367432 HIGH

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
SiemensSIMATIC Energy Manager PRO V7.4
SiemensSIMATIC WinCC Unified V19
SiemensSIMATIC IPC DiagMonitor
SiemensSIMIT V11
SiemensIndustrial Edge for Machine Tools (formerly known as "SINUMERIK Edge")
SiemensSIMATIC Energy Manager PRO V7.5
SiemensSIMATIC Energy Manager PRO V7.3
SiemensSIMATIC WinCC Unified V18
SiemensSIMATIC Energy Manager PRO V7.2
SiemensSIMATIC WinCC V8.0

Timeline

References

Open in Interactive Console →