MEDIUM4.4
GHSA-mjww-934m-h4jw
Improper Certificate Validation in OPCFoundation.NetStandard.Opc.Ua.Core
Quick fix
GHSA-mjww-934m-h4jw — OPCFoundation.NetStandard.Opc.Ua.Core: upgrade to the fixed version with the command below.
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.365.10Details
A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 allows attackers to establish a connection using invalid certificates.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/OPCFoundation.NetStandard.Opc.Ua.Core
Introduced in:
0Fixed in: 1.4.365.10Fix
dotnet add package OPCFoundation.NetStandard.Opc.Ua.Core --version 1.4.365.10References
- https://nvd.nist.gov/vuln/detail/CVE-2020-29457[ADVISORY]
- https://github.com/OPCFoundation/UA-.NETStandard/pull/1229[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard/pull/1229/commits/d815cfb972bd668c1b6e461f6ff97519d6b26f25[WEB]
- https://github.com/OPCFoundation/UA-.NETStandard[WEB]
- https://opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2020-29457.pdf[WEB]
- https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua[WEB]