QID 981078
QID 981078: Dotnet (nuget) Security Update for OPCFoundation.NetStandard.Opc.Ua (GHSA-gr4c-5rq6-cgh3)
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed bad UserIdentityTokens as part of an oracle attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gr4c-5rq6-cgh3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-gr4c-5rq6-cgh3 -
github.com/advisories/GHSA-gr4c-5rq6-cgh3
CVEs related to QID 981078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gr4c-5rq6-cgh3 | OPCFoundation.NetStandard.Opc.Ua |
|