CVE-2019-19135
Summary
| CVE | CVE-2019-19135 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-16 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Bulletins - OPC Foundation |
MISC |
opcfoundation.org |
Vendor Advisory |
| opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CV... |
CONFIRM |
opcfoundation.org |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981931 Java (maven) Security Update for org.eclipse.milo:sdk-client (GHSA-pq4w-qm9g-qx68)