A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.
References
| Link | Resource |
|---|---|
| https://github.com/OPCFoundation/UA-.NETStandard | Third Party Advisory |
| https://opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2020-29457.pdf | Patch Vendor Advisory |
| https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua/ | Product Third Party Advisory |
| https://github.com/OPCFoundation/UA-.NETStandard | Third Party Advisory |
| https://opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2020-29457.pdf | Patch Vendor Advisory |
| https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua/ | Product Third Party Advisory |
Configurations
History
21 Nov 2024, 05:24
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/OPCFoundation/UA-.NETStandard - Third Party Advisory | |
| References | () https://opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2020-29457.pdf - Patch, Vendor Advisory | |
| References | () https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua/ - Product, Third Party Advisory |
Information
Published : 2021-02-16 20:15
Updated : 2024-11-21 05:24
NVD link : CVE-2020-29457
Mitre link : CVE-2020-29457
CVE.ORG link : CVE-2020-29457
JSON object : View
Products Affected
opcfoundation
- ua-.netstandard
CWE
CWE-295
Improper Certificate Validation
