A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://github.com/OPCFoundation/UA-.NETStandard | third party advisory |
https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua/ | product third party advisory |
https://opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2020-29457.pdf | patch vendor advisory |