CVE-2019-19135

CVSS v3.1 7.4 (High)
74% Progress
CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 0.13 % (48th)
0.13% Progress
Affected Products 2
Advisories 1

In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.

Weaknesses
CWE-330
Use of Insufficiently Random Values
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2020-03-16 16:15:11
(4 years ago)
Updated Date
2021-07-21 11:39:23
(3 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Opcfoundation Netstandard.opc.ua prior 1.4.359.31 version cpe:2.3:a:opcfoundation:netstandard.opc.ua < 1.4.359.31
  Opcfoundation Ua-.netstandard 1.4.357.28 cpe:2.3:a:opcfoundation:ua-.netstandard:1.4.357.28
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...