HIGH7.5
GHSA-fvxf-r9fw-49pc
Incorrect Implementation of Authentication Algorithm in OPCFoundation.NetStandard.Opc.Ua.Core
Quick fix
GHSA-fvxf-r9fw-49pc — OPCFoundation.NetStandard.Opc.Ua.Core: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58Details
A vulnerability was discovered in the OPC UA .NET Standard Stack that - allows a malicious client or server to bypass the application authentication mechanism - and allow a connection to an untrusted peer.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Core
Introduced in:
0Fixed in: 1.4.368.58Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.368.58References
- https://github.com/OPCFoundation/UA-.NETStandard/security/advisories/GHSA-fvxf-r9fw-49pc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-29865[ADVISORY]
- https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2022-29865.pdf[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[PACKAGE]
- https://opcfoundation.org/security[WEB]