VDB
Sign up
MEDIUM5.3

GHSA-gr4c-5rq6-cgh3

OPC UA applications can allow a remote attacker to determine a Server's private key

Quick fix

GHSA-gr4c-5rq6-cgh3 — OPCFoundation.NetStandard.Opc.Ua: upgrade to the fixed version with the command below.

dotnet add package OPCFoundation.NetStandard.Opc.Ua --version 1.3.352.12

Details

An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed bad UserIdentityTokens as part of an oracle attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/OPCFoundation.NetStandard.Opc.Ua
Introduced in: 0Fixed in: 1.3.352.12
Fixdotnet add package OPCFoundation.NetStandard.Opc.Ua --version 1.3.352.12

References