Improper Certificate Validation
Affecting opcfoundation.netstandard.opc.ua package, versions [0,]
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
OPCFoundation.NetStandard.Opc.Ua is a package that contains the OPC UA reference implementation and is targeting the .NET Standard Library.
Affected versions of this package are vulnerable to Improper Certificate Validation. A privilege escalation vulnerability allows attackers to establish a connection using invalid certificates.
Remediation
There is no fixed version for OPCFoundation.NetStandard.Opc.Ua
.
References
CVSS Score
6.5
medium severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityNone
- Credit
- Unknown
- CVE
- CVE-2020-29457
- CWE
- CWE-295
- Snyk ID
- SNYK-DOTNET-OPCFOUNDATIONNETSTANDARDOPCUA-1075446
- Disclosed
- 17 Feb, 2021
- Published
- 17 Feb, 2021